5
CVSSv2

CVE-2002-1101

Published: 04/10/2002 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x prior to 3.5.5, allows remote malicious users to cause a denial of service via a long user name.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco vpn_3000_concentrator_series_software 3.0.3.b

cisco vpn_3000_concentrator_series_software 3.0.4

cisco vpn_3000_concentrator_series_software 3.1

cisco vpn_3000_concentrator_series_software 3.1\\(rel\\)

cisco vpn_3000_concentrator_series_software 2.0

cisco vpn_3000_concentrator_series_software 2.5.2.f

cisco vpn_3000_concentrator_series_software 3.0\\(rel\\)

cisco vpn_3000_concentrator_series_software 3.1.2

cisco vpn_3000_concentrator_series_software 3.5\\(rel\\)

cisco vpn_3000_concentrator_series_software 3.6\\(rel\\)

cisco vpn_3000_concentrator_series_software 2.5.2.a

cisco vpn_3000_concentrator_series_software 2.5.2.b

cisco vpn_3000_concentrator_series_software 2.5.2.c

cisco vpn_3000_concentrator_series_software 3.5.1

cisco vpn_3000_concentrator_series_software 3.5.2

cisco vpn_3000_concentrator_series_software 3.5.3

cisco vpn_3000_concentrator_series_software 3.5.4

cisco vpn_3000_concentrator_series_software 2.5.2.d

cisco vpn_3000_concentrator_series_software 3.0

cisco vpn_3000_concentrator_series_software 3.0.3.a

cisco vpn_3000_concentrator_series_software 3.1.1

cisco vpn_3000_concentrator_series_software 3.1.4

cisco vpn_3002_hardware_client

Exploits

source: wwwsecurityfocuscom/bid/5620/info Cisco VPN 3000 series concentrators are prone to a denial of service condition when receiving an overly long username string during authentication from a VPN client Successful exploitation will cause the device to reload /* ISAKMP Cisco VPN Concentrator DoS * by nowin of Phenoelit <nowin ...