Vulnerabilities > Cisco > ONS 15454

DATE CVE VULNERABILITY TITLE RISK
2014-04-12 CVE-2014-2142 Denial of Service vulnerability in Cisco products
Cisco ONS 15454 controller cards with software 10.0 and earlier allow remote attackers to cause a denial of service (card reload) via a crafted HTTP URI, aka Bug ID CSCun06870.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2140 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (card reset) via a TCP FIN attack that triggers file-descriptor exhaustion and a failure to open a CAL pipe, aka Bug ID CSCug97348.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2139 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (flash write outage) via a TCP FIN attack that triggers file-descriptor exhaustion, aka Bug ID CSCug97315.
network
low complexity
cisco
5.0
2014-04-10 CVE-2014-2141 Buffer Errors vulnerability in Cisco ONS 15454 System Software and ONS 15454
The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.
network
low complexity
cisco CWE-119
4.0
2013-12-18 CVE-2013-6701 Improper Input Validation vulnerability in Cisco products
The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via a flood of network traffic, aka Bug ID CSCud97155.
network
low complexity
cisco CWE-20
5.0
2013-12-04 CVE-2013-6702 Improper Input Validation vulnerability in Cisco ONS 15454 and ONS 15454 Firmware
The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packets, aka Bug ID CSCtz50902.
network
cisco CWE-20
4.3
2013-12-03 CVE-2013-6703 Improper Input Validation vulnerability in Cisco ONS 15454
The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2) SSLv3 packets, aka Bug ID CSCuh34787.
network
cisco CWE-20
7.1
2009-01-16 CVE-2008-3818 Improper Input Validation vulnerability in Cisco ONS and ONS 15600
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted TCP session.
network
low complexity
cisco CWE-20
7.8