7.5
CVE-2006-1672
- EPSS 3.8%
- Published 07.04.2006 10:04:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Transport Controller Version4.0.x
Cisco ≫ Optical Networking Systems Software Version1.0
Cisco ≫ Optical Networking Systems Software Version1.1
Cisco ≫ Optical Networking Systems Software Version3.0
Cisco ≫ Optical Networking Systems Software Version3.1.0
Cisco ≫ Optical Networking Systems Software Version3.2
Cisco ≫ Optical Networking Systems Software Version3.3.0
Cisco ≫ Optical Networking Systems Software Version3.4.0
Cisco ≫ Optical Networking Systems Software Version4.0.0
Cisco ≫ Optical Networking Systems Software Version4.1.4
Cisco ≫ Ons 15310-cl Series Version0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.8% | 0.87 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|