Vulnerabilities > Cisco > Cisco ONS 15454 System Software

DATE CVE VULNERABILITY TITLE RISK
2014-04-12 CVE-2014-2142 Denial of Service vulnerability in Cisco products
Cisco ONS 15454 controller cards with software 10.0 and earlier allow remote attackers to cause a denial of service (card reload) via a crafted HTTP URI, aka Bug ID CSCun06870.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2140 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (card reset) via a TCP FIN attack that triggers file-descriptor exhaustion and a failure to open a CAL pipe, aka Bug ID CSCug97348.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2139 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (flash write outage) via a TCP FIN attack that triggers file-descriptor exhaustion, aka Bug ID CSCug97315.
network
low complexity
cisco
5.0
2014-04-10 CVE-2014-2141 Buffer Errors vulnerability in Cisco ONS 15454 System Software and ONS 15454
The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.
network
low complexity
cisco CWE-119
4.0
2013-12-18 CVE-2013-6701 Improper Input Validation vulnerability in Cisco products
The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via a flood of network traffic, aka Bug ID CSCud97155.
network
low complexity
cisco CWE-20
5.0