ID

VAR-200210-0246


CVE

CVE-2002-1093


TITLE

Cisco HTTP Interface Long Request Denial Of Service Vulnerability

Trust: 0.9

sources: BID: 5615 // CNNVD: CNNVD-200210-069

DESCRIPTION

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request. Cisco VPN 3000 series concentrators are a family of products for facilitating secure communications via VPN (Virtual Private Networks). By placing a malicious HTTP request to a vulnerable system, the system becomes unstable

Trust: 1.26

sources: NVD: CVE-2002-1093 // BID: 5615 // VULHUB: VHN-5481

AFFECTED PRODUCTS

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.5.2

Trust: 1.5

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.0

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.f

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.b

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.3.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.c

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.d

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.a

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.0\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.f

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.0.3.a

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.d

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.c

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.0

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.b

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.0

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0.3

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.5

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.0.3

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.3

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.0.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.2

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.0

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.2

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.1

Trust: 0.3

sources: BID: 5615 // CNNVD: CNNVD-200210-069 // NVD: CVE-2002-1093

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1093
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200210-069
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5481
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1093
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5481
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5481 // CNNVD: CNNVD-200210-069 // NVD: CVE-2002-1093

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1093

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200210-069

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200210-069

EXTERNAL IDS

db:BIDid:5615

Trust: 2.0

db:NVDid:CVE-2002-1093

Trust: 2.0

db:CNNVDid:CNNVD-200210-069

Trust: 0.7

db:CISCOid:20020903 CISCO VPN 3000 CONCENTRATOR MULTIPLE VULNERABILITIES

Trust: 0.6

db:XFid:10018

Trust: 0.6

db:VULHUBid:VHN-5481

Trust: 0.1

sources: VULHUB: VHN-5481 // BID: 5615 // CNNVD: CNNVD-200210-069 // NVD: CVE-2002-1093

REFERENCES

url:http://www.securityfocus.com/bid/5615

Trust: 1.7

url:http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

Trust: 1.7

url:http://www.iss.net/security_center/static/10018.php

Trust: 1.7

sources: VULHUB: VHN-5481 // CNNVD: CNNVD-200210-069 // NVD: CVE-2002-1093

CREDITS

Vulnerability announced in a Cisco Security Advisory.

Trust: 0.9

sources: BID: 5615 // CNNVD: CNNVD-200210-069

SOURCES

db:VULHUBid:VHN-5481
db:BIDid:5615
db:CNNVDid:CNNVD-200210-069
db:NVDid:CVE-2002-1093

LAST UPDATE DATE

2024-08-14T14:16:15.811000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5481date:2018-10-30T00:00:00
db:BIDid:5615date:2009-07-11T15:56:00
db:CNNVDid:CNNVD-200210-069date:2005-05-13T00:00:00
db:NVDid:CVE-2002-1093date:2018-10-30T16:26:16.373

SOURCES RELEASE DATE

db:VULHUBid:VHN-5481date:2002-10-04T00:00:00
db:BIDid:5615date:2002-09-03T00:00:00
db:CNNVDid:CNNVD-200210-069date:2002-10-04T00:00:00
db:NVDid:CVE-2002-1093date:2002-10-04T04:00:00