CVE-2013-6702: Input Validation
Published Dec 4, 2013
·Updated
The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packets, aka Bug ID CSCtz50902.
Affected Software
4 affected components
Cisco Ons 15454 Firmware<=9.8
Cisco ONS 15454
All of the following
Cisco Ons 15454 Firmware<=9.8
Cisco ONS 15454
Event History
Dec 4, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·06:56 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6702?
CVE-2013-6702 is considered a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2013-6702?
To fix CVE-2013-6702, update the Cisco ONS 15454 firmware to version 9.9 or later.
3
What impact does CVE-2013-6702 have on my Cisco ONS 15454?
CVE-2013-6702 could lead to a denial of service that causes the card to reset unexpectedly.
4
Is CVE-2013-6702 remotely exploitable?
Yes, CVE-2013-6702 can be exploited remotely by attackers via crafted packets.
5
Which versions of Cisco ONS 15454 are affected by CVE-2013-6702?
Cisco ONS 15454 devices running software versions 9.8 and earlier are affected by CVE-2013-6702.