CVE-2004-1436

UnknownEPSS 3.14%

Last modified

CVE-2004-1436 is a vulnerability of currently unknown severity. The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.. EPSS estimates a 3.14% chance of exploitation in the next 30 days.

Description

The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.

Metrics

EPSS Probability
3.14%

86.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoOptical Networking Systems Software1.0
CiscoOptical Networking Systems Software1.1
CiscoOptical Networking Systems Software1.1\(0\)
CiscoOptical Networking Systems Software1.1\(1\)
CiscoOptical Networking Systems Software1.3\(0\)
CiscoOptical Networking Systems Software2.3\(5\)
CiscoOptical Networking Systems Software3.0
CiscoOptical Networking Systems Software3.1.0
CiscoOptical Networking Systems Software3.2
CiscoOptical Networking Systems Software3.2.0
CiscoOptical Networking Systems Software3.3.0
CiscoOptical Networking Systems Software3.4.0
CiscoOptical Networking Systems Software4.0\(0\)
CiscoOptical Networking Systems Software4.0\(1\)
CiscoOptical Networking Systems Software4.0\(2\)
CiscoOptical Networking Systems Software4.0.0
CiscoOptical Networking Systems Software4.1\(0\)
CiscoOptical Networking Systems Software4.1\(1\)
CiscoOptical Networking Systems Software4.1\(2\)
CiscoOptical Networking Systems Software4.1\(3\)
CiscoOptical Networking Systems Software4.5
CiscoOptical Networking Systems Software4.6\(0\)
CiscoOptical Networking Systems Software4.6\(1\)

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-1436?
The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.
How severe is CVE-2004-1436?
Severity scoring for CVE-2004-1436 is pending analysis. The EPSS model estimates a 3.14% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1436?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-1436?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST