2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2006-1672" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2006-04-07T10:04:00.000" ,
2024-11-22 03:16:05 +00:00
"lastModified" : "2024-11-21T00:09:27.163" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing \"fs/LAUNCHER.jar\", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
2024-11-22 03:16:05 +00:00
"baseScore" : 7.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-22 03:16:05 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : true ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:transport_controller:4.0.x:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A5F7F982-4359-4107-843C-E54CDA4A9E89"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D1888FF-6126-4F40-A7EA-1ED5123FA729"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "15B6D45F-25A7-4055-9D9C-42DEACBFFE17"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:1.1\\(0\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "31461FAA-2F90-47B0-BDA3-D81A8186960C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:1.1\\(1\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2EF8D104-CABD-4036-A4AF-68B80D83AE34"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:1.3\\(0\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5331AAD2-7E21-4407-9DF7-9D2A8058FAE0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B0A4FA3-45F4-47B7-BA5B-6AEC8DB14C9E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:3.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6509622E-7E8D-4238-92F2-7DB88A3DB4DA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80460930-7D3D-4315-8D00-FFDCDBA69477"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:3.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0993B9A9-599B-4662-AEC2-EC771BCE8200"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:3.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "04472ED2-EB97-47E1-938E-D69C363E81C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.0\\(1\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10988AA9-A807-4E70-8197-6F9EFC13AE86"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.0\\(2\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C8951276-CDEF-4F54-93DF-B96DB10E6530"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D886A75-5A73-4B1C-8B2A-45D589267B37"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.1\\(0\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5A594C2-98BB-4AC5-9CC5-89FE97D63323"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.1\\(1\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B35325A-98F6-41DF-ADD8-91ED992A3ED3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.1\\(2\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0B06C5B-73C2-47F1-9ED6-B59F9C1C5AF1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.1\\(3\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D9758019-F6EA-4552-B070-5A9EBE73BB86"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44DDAC96-7467-4FFF-B337-C0475B7214B0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.6\\(0\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4DEC7814-61D4-420A-AB81-6720F3C2D6B9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cisco:optical_networking_systems_software:4.6\\(1\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "413133A5-F600-4B2B-82E1-3EAC10B7E6F9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:cisco:ons_15310-cl_series:0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "727F672F-6227-4DF3-86A7-A259F97EB92E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:cisco:ons_15600:0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D6E7CD66-ADA5-4397-9A59-E5C6B51B8A2F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:ons_15454_mspp:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B0E3A7E4-39CD-44B9-B72D-0C9B810A2158"
}
]
}
]
}
] ,
"references" : [
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/19553" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://securitytracker.com/id?1015871" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml" ,
"source" : "cve@mitre.org"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://www.osvdb.org/24438" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.securityfocus.com/bid/17384" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2006/1256" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25647" ,
"source" : "cve@mitre.org"
2024-11-22 03:16:05 +00:00
} ,
{
"url" : "http://secunia.com/advisories/19553" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://securitytracker.com/id?1015871" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.osvdb.org/24438" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/17384" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2006/1256" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/25647" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}