← Vulnerability feed

Vulnerability record · CVE-2002-1557 · published 31 March 2003

CVE-2002-1557: Cisco optical networking systems software vulnerability

Cisco · Optical Networking Systems Software

Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.

5.0 CVSS 2.0 Medium EPSS 1.4% · top 28.8%
5.0CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0308Cisco optical networking systems software vulnerabilityUnknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows …EPSS 1.7%10.0CVE-2002-1558Cisco optical networking systems software vulnerabilityCisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed o…EPSS 2.8%7.8CVE-2006-1670Cisco optical networking systems software vulnerabilityControl cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memor…EPSS 2.3%7.8CVE-2003-0567Cisco ios improper input validation vulnerabilityCisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 pa…EPSS 17%7.5CVE-2006-1672Cisco transport controller vulnerabilityThe installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with …EPSS 4.1%7.5CVE-2004-1436Cisco optical networking systems software vulnerabilityThe Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account …EPSS 3.1%7.5CVE-2002-1553Cisco optical networking systems software vulnerabilityCisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP…EPSS 1.6%5.0CVE-2006-1671Cisco transport controller vulnerabilityControl cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card …EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2002-1557), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.