ID

VAR-200210-0248


CVE

CVE-2002-1095


TITLE

Cisco VPN Concentrator PPTP Client Remote service denial vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200210-201

DESCRIPTION

Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set. Cisco VPN 3000 series concentrators are a family of products for facilitating secure communications via VPN (Virtual Private Networks). Under some circumstances, it may be possible for a remote PPTP client to cause a denial of service. This could result in a denial of service to legitimate users of the device. Cisco VPN 3000 Concentrator versions earlier than 2.5.2(F) have vulnerabilities

Trust: 1.26

sources: NVD: CVE-2002-1095 // BID: 5625 // VULHUB: VHN-5483

AFFECTED PRODUCTS

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.5.2

Trust: 1.2

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.0

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.a

Trust: 1.0

vendor:ciscomodel:vpn 3002 hardware clientscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.b

Trust: 1.0

vendor:ciscomodel:secure access control serverscope:eqversion:2.6.3

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.c

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.d

Trust: 1.0

vendor:ciscomodel:vpn concentratorscope:neversion:30003.0.3

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.a

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.d

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.c

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.0

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:2.5.2.b

Trust: 0.6

vendor:ciscomodel:vpn hardware clientscope:eqversion:3002

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.0

Trust: 0.3

vendor:ciscomodel:secure acs for windows ntscope:eqversion:2.6.3

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.5

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.3

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.2

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.2

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.0.4

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.0

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30002.5.2

Trust: 0.3

sources: BID: 5625 // CNNVD: CNNVD-200210-201 // NVD: CVE-2002-1095

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1095
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200210-201
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5483
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1095
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5483
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5483 // CNNVD: CNNVD-200210-201 // NVD: CVE-2002-1095

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1095

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200210-201

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200210-201

EXTERNAL IDS

db:BIDid:5625

Trust: 2.0

db:NVDid:CVE-2002-1095

Trust: 2.0

db:CNNVDid:CNNVD-200210-201

Trust: 0.7

db:XFid:10021

Trust: 0.6

db:CISCOid:20020903 CISCO VPN 3000 CONCENTRATOR MULTIPLE VULNERABILITIES

Trust: 0.6

db:VULHUBid:VHN-5483

Trust: 0.1

sources: VULHUB: VHN-5483 // BID: 5625 // CNNVD: CNNVD-200210-201 // NVD: CVE-2002-1095

REFERENCES

url:http://www.securityfocus.com/bid/5625

Trust: 1.7

url:http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

Trust: 1.7

url:http://www.iss.net/security_center/static/10021.php

Trust: 1.7

sources: VULHUB: VHN-5483 // CNNVD: CNNVD-200210-201 // NVD: CVE-2002-1095

CREDITS

Vulnerability announced in a Cisco Security Advisory.

Trust: 0.9

sources: BID: 5625 // CNNVD: CNNVD-200210-201

SOURCES

db:VULHUBid:VHN-5483
db:BIDid:5625
db:CNNVDid:CNNVD-200210-201
db:NVDid:CVE-2002-1095

LAST UPDATE DATE

2024-08-14T14:16:19.260000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5483date:2018-10-30T00:00:00
db:BIDid:5625date:2009-07-11T15:56:00
db:CNNVDid:CNNVD-200210-201date:2005-10-12T00:00:00
db:NVDid:CVE-2002-1095date:2018-10-30T16:26:16.373

SOURCES RELEASE DATE

db:VULHUBid:VHN-5483date:2002-10-04T00:00:00
db:BIDid:5625date:2002-09-03T00:00:00
db:CNNVDid:CNNVD-200210-201date:2002-10-04T00:00:00
db:NVDid:CVE-2002-1095date:2002-10-04T04:00:00