Back to Database
Status published
High
CVE-2005-4197
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to...
Vulnerability Description
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-4197
Credits & Attribution
No credits recorded in the NVD database.
References
More from nortel
View All →CVE-2008-6579
Nortel Communication Server 1000 4.50.x allows remote attackers to obtain...
Medium
5
CVE-2008-6578
Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow...
Critical
10
CVE-2008-6577
Nortel MG1000S, Signaling Server, and Call Server on the Communications...
Critical
10
CVE-2008-6576
Unspecified vulnerability in the "session limitation technique" in the FTP...
High
7.8
CVE-2008-6564
Nortel UNIStim protocol, as used in Communication Server 1000 and...
High
7.6
Affected Vendor
nortel
View all reports →Affected Software
ssl vpn
Vulnerable Versions:
0, 4.1.2.11, 4.1.2.12
Timeline
Official Publish:
December 13th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.