Tracker / CVE-2006-1672
CVE-2006-1672
High 7.5
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
Affected products and versions
| cisco | ons_15310-cl_series |
|---|---|
| cisco | ons_15454_mspp |
| cisco | ons_15600 |
| cisco | optical_networking_systems_software |
| cisco | transport_controller |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.