Title: Cisco ONS Multiple Vulnerabilities
Severity: HIGH
Description:
Cisco ONS platforms are prone to multiple vulnerabilities. The following specific vulnerabilities were reported:
- Malformed IP packets may cause a denial of service in XTC, TCC/TCC+/TCC2, and TCCi/TCC2 control cards. This condition may be exploited repeatedly to cause both the active and standby control cards to reset simultaneously. Cisco ONS 15600 hardware is not affected by this issue.
- Malformed ICMP packets may cause a denial of service in XTC, TCC/TCC+/TCC2, and TCCi/TCC2 control cards. This condition may be exploited repeatedly to cause both the active and standby control cards to reset simultaneously. Cisco ONS 15600 hardware is not affected by this issue.
- Malformed TCP packets may cause a denial of service in XTC, TCC/TCC+/TCC2, TCCi/TCC2, and TSC control cards. This condition may be exploited repeatedly to cause both the active and standby control cards to reset simultaneously. The issue reportedly will not affect traffic on Cisco ONS 15600 devices but may impact management functions.
- XTC, TCC/TCC+/TCC2, and TCCi/TCC2 control cards are prone to a TCP-ACK related denial of service. This condition may occur when the final ACK packet is not sent during the TCP 3-way handshake and an invalid response is sent instead. This will cause the connection to enter into an invalid state. Exploitation will reportedly cause control cards to reset. Cisco ONS 15600 is not affected by the issue.
- Malformed UDP packets may cause a denial of service in XTC, TCC/TCC+/TCC2, TCCi/TCC2, and TSC control cards. This condition may be exploited repeatedly to cause both the active and standby control cards to reset simultaneously. The issue reportedly will not affect traffic on Cisco ONS 15600 devices but may impact management functions.
- Malformed SNMP packets may cause a denial of service in XTC, TCC/TCC+/TCC2, and TCCi/TCC2 control cards. This condition may be exploited repeatedly to cause both the active and standby control cards to reset simultaneously. Cisco ONS 15600 hardware is not affected by this issue.
- An authentication bypass issue was reported in the TL1 login interface. If a blank password is set, the interface may reportedly allow users to gain unauthorized access by submitting a password that is greater than ten characters. This reportedly only affects the CISCO15 userid, which has a blank password by default. The TL1 login interface does not allow a blank password to be manually set otherwise. Cisco ONS 15600 hardware is not affected by this issue.
The issues in this cumulative BID are undergoing further analysis and will be assigned individual BIDs for each distinct vulnerability at a later time.
Affected Products:
- Cisco ONS 15327 3.0.0
- Cisco ONS 15327 3.1.0
- Cisco ONS 15327 3.2.0
- Cisco ONS 15327 3.3.0
- Cisco ONS 15327 3.4.0
- Cisco ONS 15327 4.0.0
- Cisco ONS 15327 4.0.0(1)
- Cisco ONS 15327 4.0.0(2)
- Cisco ONS 15327 4.1.0(0)
- Cisco ONS 15327 4.1.0(1)
- Cisco ONS 15327 4.1.0(2)
- Cisco ONS 15327 4.1.0(3)
- Cisco ONS 15327 4.6.0(0)
- Cisco ONS 15327 4.6.0(1)
- Cisco ONS 15454 Optical Transport Platform 2.3.0 (5)
- Cisco ONS 15454 Optical Transport Platform 3.0.0
- Cisco ONS 15454 Optical Transport Platform 3.1.0 .0
- Cisco ONS 15454 Optical Transport Platform 3.2.0 .0
- Cisco ONS 15454 Optical Transport Platform 3.3.0
- Cisco ONS 15454 Optical Transport Platform 3.4.0
- Cisco ONS 15454 Optical Transport Platform 4.0.0
- Cisco ONS 15454 Optical Transport Platform 4.0.0 (1)
- Cisco ONS 15454 Optical Transport Platform 4.0.0 (2)
- Cisco ONS 15454 Optical Transport Platform 4.1.0 (0)
- Cisco ONS 15454 Optical Transport Platform 4.1.0 (1)
- Cisco ONS 15454 Optical Transport Platform 4.1.0 (2)
- Cisco ONS 15454 Optical Transport Platform 4.1.0 (3)
- Cisco ONS 15454 Optical Transport Platform 4.5.0
- Cisco ONS 15454 Optical Transport Platform 4.6.0 (0)
- Cisco ONS 15454 Optical Transport Platform 4.6.0 (1)
- Cisco ONS 15454SDH 2.3.0 (5)
- Cisco ONS 15454SDH 3.1.0
- Cisco ONS 15454SDH 3.2.0
- Cisco ONS 15454SDH 3.3.0
- Cisco ONS 15454SDH 3.4.0
- Cisco ONS 15454SDH 4.0.0 (0)
- Cisco ONS 15454SDH 4.0.0 (1)
- Cisco ONS 15454SDH 4.0.0 (2)
- Cisco ONS 15454SDH 4.1.0 (0)
- Cisco ONS 15454SDH 4.1.0 (1)
- Cisco ONS 15454SDH 4.1.0 (2)
- Cisco ONS 15454SDH 4.1.0 (3)
- Cisco ONS 15454SDH 4.5.0
- Cisco ONS 15454SDH 4.6.0 (0)
- Cisco ONS 15454SDH 4.6.0 (1)
- Cisco ONS 15600 1.0.0
- Cisco ONS 15600 1.1.0
- Cisco ONS 15600 1.1.0(0)
- Cisco ONS 15600 1.1.0(1)
- Cisco ONS 15600 1.3.0(0)
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.