First published: Fri Apr 07 2006(Updated: )
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a "crafted" IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a "malformed" OSPF packet, aka bug ID CSCsc54558.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Transport Controller | =4.0.x | |
Cisco ONS 15454 SDH | ||
Cisco ONS 15600 | =0 | |
Cisco ONS 15310-CL Series | =0 | |
Cisco Optical Networking systems software | =3.2 | |
Cisco Optical Networking systems software | =3.3.0 | |
Cisco Optical Networking systems software | =3.4.0 | |
Cisco Optical Networking systems software | =4.0.0 | |
Cisco Optical Networking systems software | =3.1.0 | |
Cisco Optical Networking systems software | =4.6\(1\) | |
Cisco Optical Networking systems software | =1.0 | |
Cisco Optical Networking systems software | =1.1 | |
Cisco Optical Networking systems software | =1.1\(0\) | |
Cisco Optical Networking systems software | =1.1\(1\) | |
Cisco Optical Networking systems software | =4.1\(2\) | |
Cisco Optical Networking systems software | =4.1\(3\) | |
Cisco Optical Networking systems software | =4.1.4 | |
Cisco Optical Networking systems software | =4.6\(0\) | |
Cisco Optical Networking systems software | =4.0\(2\) | |
Cisco Optical Networking systems software | =4.1\(0\) | |
Cisco Optical Networking systems software | =4.1\(1\) | |
Cisco Optical Networking systems software | =4.0\(1\) | |
Cisco Optical Networking systems software | =1.3\(0\) | |
Cisco Optical Networking systems software | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1671 is classified as a denial of service vulnerability that can lead to a card reset in affected devices.
To mitigate CVE-2006-1671, users should upgrade their Cisco Optical Networking System software to a version released after April 2006.
CVE-2006-1671 affects various Cisco Optical Networking System devices, including the ONS 15000 series and Transport Controller versions prior to the fixes.
CVE-2006-1671 allows remote attackers to send crafted IP packets that can trigger a denial of service condition.
As of the last update, there is no public evidence indicating that CVE-2006-1671 is being actively exploited in the wild.