Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Vpn_3000_concentrator_series_software
(Cisco)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 24 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2003-05-27 | CVE-2003-0258 | Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client, Vpn_3005_concentrator_software, Vpn_3015_concentrator, Vpn_3030_concentator, Vpn_3060_concentrator, Vpn_3080_concentrator | N/A | ||
2002-10-04 | CVE-2002-1103 | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1102 | The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1101 | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1100 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1099 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1098 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1097 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1096 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code. | Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A | ||
2002-10-04 | CVE-2002-1095 | Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set. | Secure_access_control_server, Vpn_3000_concentrator_series_software, Vpn_3002_hardware_client | N/A |