ID

VAR-200210-0247


CVE

CVE-2002-1094


TITLE

Cisco VPN Concentrator HTTP Error page device information disclosure vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200210-217

DESCRIPTION

Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request. Cisco VPN 3000 series concentrators are a family of products for facilitating secure communications via VPN (Virtual Private Networks). Under some circumstances, it may be possible for a remote user to gain access to sensitive information. The SSH banner reveals more information than necessary to negotiate a session. This could lead to intelligence gathering, and a directed attack against network resources. Cisco VPN 3000 Concentrator versions 2.xx and 3.xx prior to 3.5.4 have an information disclosure vulnerability

Trust: 1.8

sources: NVD: CVE-2002-1094 // BID: 5623 // BID: 5624 // BID: 5621 // VULHUB: VHN-5482

AFFECTED PRODUCTS

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.5.2

Trust: 4.5

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0.3

Trust: 1.8

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.0

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.3.b

Trust: 1.0

vendor:ciscomodel:vpn 3002 hardware clientscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.b

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.4

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.3.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.c

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.d

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.2

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.4

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.1

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.f

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.3

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.2

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.1

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0

Trust: 1.0

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.3

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0.4

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.4

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.5

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.2

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.4

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.1

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.2

Trust: 0.9

vendor:ciscomodel:vpn hardware clientscope:eqversion:3002

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.0

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6.1

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.1

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1

Trust: 0.9

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.1

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.2

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.3

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.4

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.1

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.2

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.0.3.b

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.0.4

Trust: 0.6

sources: BID: 5623 // BID: 5624 // BID: 5621 // CNNVD: CNNVD-200210-217 // NVD: CVE-2002-1094

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1094
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200210-217
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5482
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1094
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5482
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5482 // CNNVD: CNNVD-200210-217 // NVD: CVE-2002-1094

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1094

THREAT TYPE

network

Trust: 0.9

sources: BID: 5623 // BID: 5624 // BID: 5621

TYPE

Configuration Error

Trust: 1.5

sources: BID: 5623 // BID: 5624 // BID: 5621 // CNNVD: CNNVD-200210-217

EXTERNAL IDS

db:NVDid:CVE-2002-1094

Trust: 2.6

db:BIDid:5624

Trust: 2.0

db:BIDid:5621

Trust: 2.0

db:BIDid:5623

Trust: 2.0

db:CNNVDid:CNNVD-200210-217

Trust: 0.7

db:CISCOid:20020903 CISCO VPN 3000 CONCENTRATOR MULTIPLE VULNERABILITIES

Trust: 0.6

db:XFid:10020

Trust: 0.6

db:VULHUBid:VHN-5482

Trust: 0.1

sources: VULHUB: VHN-5482 // BID: 5623 // BID: 5624 // BID: 5621 // CNNVD: CNNVD-200210-217 // NVD: CVE-2002-1094

REFERENCES

url:http://www.securityfocus.com/bid/5621

Trust: 1.7

url:http://www.securityfocus.com/bid/5623

Trust: 1.7

url:http://www.securityfocus.com/bid/5624

Trust: 1.7

url:http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

Trust: 1.7

url:http://www.iss.net/security_center/static/10020.php

Trust: 1.7

sources: VULHUB: VHN-5482 // CNNVD: CNNVD-200210-217 // NVD: CVE-2002-1094

CREDITS

Vulnerability announced in a Cisco Security Advisory.

Trust: 1.5

sources: BID: 5623 // BID: 5624 // BID: 5621 // CNNVD: CNNVD-200210-217

SOURCES

db:VULHUBid:VHN-5482
db:BIDid:5623
db:BIDid:5624
db:BIDid:5621
db:CNNVDid:CNNVD-200210-217
db:NVDid:CVE-2002-1094

LAST UPDATE DATE

2024-08-14T14:16:15.751000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5482date:2018-10-30T00:00:00
db:BIDid:5623date:2009-07-11T15:56:00
db:BIDid:5624date:2009-07-11T15:56:00
db:BIDid:5621date:2009-07-11T15:56:00
db:CNNVDid:CNNVD-200210-217date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1094date:2018-10-30T16:26:19.107

SOURCES RELEASE DATE

db:VULHUBid:VHN-5482date:2002-10-04T00:00:00
db:BIDid:5623date:2002-09-03T00:00:00
db:BIDid:5624date:2002-09-03T00:00:00
db:BIDid:5621date:2002-09-03T00:00:00
db:CNNVDid:CNNVD-200210-217date:2002-10-04T00:00:00
db:NVDid:CVE-2002-1094date:2002-10-04T04:00:00