7.5
CVSSv2

CVE-2006-1672

Published: 07/04/2006 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote malicious users to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco transport controller 4.0.x

cisco optical networking systems software 3.3.0

cisco optical networking systems software 3.4.0

cisco optical networking systems software 4.1\\(3\\)

cisco optical networking systems software 4.1.4

cisco optical networking systems software 1.3\\(0\\)

cisco ons 15310-cl series 0

cisco optical networking systems software 4.0.0

cisco optical networking systems software 4.0\\(1\\)

cisco optical networking systems software 4.6\\(0\\)

cisco optical networking systems software 4.6\\(1\\)

cisco ons 15600 0

cisco optical networking systems software 3.0

cisco optical networking systems software 4.0\\(2\\)

cisco optical networking systems software 4.1\\(0\\)

cisco ons 15454 mspp

cisco optical networking systems software 1.0

cisco optical networking systems software 1.1

cisco optical networking systems software 3.1.0

cisco optical networking systems software 3.2

cisco optical networking systems software 4.1\\(1\\)

cisco optical networking systems software 4.1\\(2\\)

cisco optical networking systems software 1.1\\(0\\)

cisco optical networking systems software 1.1\\(1\\)

Vendor Advisories

Multiple vulnerabilities exist in the Cisco Optical Networking System (ONS) 15310 Multi-service Provisioning Platforms (MSPP), ONS 15327 MSPP, ONS 15454 MSPP, ONS 15454 Multi-service Transport Platform (MSTP) and the ONS 15600 MSPP These vulnerabilities will affect Optical nodes that have the Common Control Cards connected to a Data Commun ...