[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1436Date: (C)2004-12-31   (M)2023-12-22


The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-10768
SECUNIA-12117
http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml
VU#760432
cisco-ons-tl1-auth-bypass(16766)

CPE    10
cpe:/a:cisco:optical_networking_systems_software:1.0
cpe:/a:cisco:optical_networking_systems_software:1.1
cpe:/a:cisco:optical_networking_systems_software:3.0
cpe:/a:cisco:optical_networking_systems_software:3.2
...

© SecPod Technologies