7.5
CVE-2006-1672
- EPSS 3.8%
- Veröffentlicht 07.04.2006 10:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Transport Controller Version4.0.x
Cisco ≫ Optical Networking Systems Software Version1.0
Cisco ≫ Optical Networking Systems Software Version1.1
Cisco ≫ Optical Networking Systems Software Version3.0
Cisco ≫ Optical Networking Systems Software Version3.1.0
Cisco ≫ Optical Networking Systems Software Version3.2
Cisco ≫ Optical Networking Systems Software Version3.3.0
Cisco ≫ Optical Networking Systems Software Version3.4.0
Cisco ≫ Optical Networking Systems Software Version4.0.0
Cisco ≫ Optical Networking Systems Software Version4.1.4
Cisco ≫ Ons 15310-cl Series Version0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.8% | 0.87 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|