Cisco IPsec VPN Implementation Group Name Enumeration Information Disclosure Vulnerability

Related Vulnerabilities: CVE-2010-4354  

Multiple Cisco VPN devices contain a vulnerability that could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability exists due to unsafe handling of error response codes. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious requests to the targeted device. If successful, the attacker could determine the existence of VPN group names in use on the device. Cisco has confirmed the vulnerability in a security response and released software updates. Because the affected devices typically accept unsolicited connections from untrusted networks, an attacker could easily target a vulnerable system.  If an exploit is successful, the attacker could gain access to sensitive information about the device that could aid the attacker in further exploits. Administrators should note that Cisco PIX 500 Series devices and Cisco VPN 300 Series Concentrators have reached end of life.  As a result, no software updates will be issued for these products.