← Vulnerability feed

Vulnerability record · CVE-2006-1672 · published 7 April 2006

CVE-2006-1672: Cisco transport controller vulnerability

Cisco · Transport Controller

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.

7.5 CVSS 2.0 High EPSS 4.1% · top 9.6%
7.5CVSS 2.0 base score
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-1672 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0308Cisco optical networking systems software vulnerabilityUnknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows …EPSS 1.7%10.0CVE-2002-1558Cisco optical networking systems software vulnerabilityCisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed o…EPSS 2.8%7.8CVE-2008-3818Cisco ons improper input validation vulnerabilityCisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote atta…EPSS 2.0%7.8CVE-2006-1670Cisco optical networking systems software vulnerabilityControl cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memor…EPSS 2.3%7.8CVE-2003-0567Cisco ios improper input validation vulnerabilityCisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 pa…EPSS 17%7.5CVE-2004-1436Cisco optical networking systems software vulnerabilityThe Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account …EPSS 3.1%7.5CVE-2002-1553Cisco optical networking systems software vulnerabilityCisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP…EPSS 1.6%5.0CVE-2013-6701Cisco ons 15454 system software improper input validation vulnerabilityThe tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritiz…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2006-1672), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.