ID

VAR-200210-0274


CVE

CVE-2002-1103


TITLE

Cisco VPN 3000 series concentrator does not properly handle malformed ISAKMP packets

Trust: 0.8

sources: CERT/CC: VU#761651

DESCRIPTION

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets. Cisco VPN 3000 series concentrators do not properly handle specially crafted Internet Security Association and Key Management Protocol (ISAKMP) packets, which can cause a vulnerable device to reload, denying service to legitimate users. Denial of network/VPN service may be possible. Cisco has reported a number of vulnerabilities in the VPN 3000 series concentrators. These issues affect models 3005, 3015, 3030, 3060, 3080 and the Cisco VPN 3002 Hardware Client. The nature of these issues varies from disclosure of sensitive information, to denial of service. Some of these issues may allow for remote unauthorized access to the device or the network to occur. VPN 3000 Concentrator is prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause denial-of-service conditions

Trust: 2.52

sources: NVD: CVE-2002-1103 // CERT/CC: VU#761651 // BID: 5619 // BID: 5609 // BID: 89573 // VULHUB: VHN-5491

AFFECTED PRODUCTS

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.5.2

Trust: 4.5

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0.3

Trust: 1.5

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1

Trust: 1.2

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.0

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.3.b

Trust: 1.0

vendor:ciscomodel:vpn 3002 hardware clientscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.b

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.4

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0.3.a

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.c

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.d

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.2

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.1

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1.4

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:2.5.2.f

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.4

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.1\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.3

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.2

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.5.1

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.6\(rel\)

Trust: 1.0

vendor:ciscomodel:vpn 3000 concentrator series softwarescope:eqversion:3.0

Trust: 1.0

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.3

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.4

Trust: 0.9

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.1

Trust: 0.9

vendor:ciscomodel:vpn hardware clientscope:eqversion:3002

Trust: 0.9

vendor:ciscomodel: - scope: - version: -

Trust: 0.8

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0.4

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.4

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.0

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.2

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.1.2

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30002.0

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.5.1

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.6\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.1

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.2

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.3

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.1.4

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5\(rel\)

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.4

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.1

Trust: 0.6

vendor:ciscomodel:vpn 3000 concentratorscope:eqversion:3.5.2

Trust: 0.6

vendor:ciscomodel:vpn concentratorscope:neversion:30003.5.5

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:neversion:30003.6.1

Trust: 0.3

vendor:ciscomodel:vpn concentratorscope:eqversion:30003.6

Trust: 0.3

sources: CERT/CC: VU#761651 // BID: 5619 // BID: 5609 // BID: 89573 // CNNVD: CNNVD-200210-038 // NVD: CVE-2002-1103

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1103
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#761651
value: 7.73

Trust: 0.8

CNNVD: CNNVD-200210-038
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5491
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1103
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5491
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#761651 // VULHUB: VHN-5491 // CNNVD: CNNVD-200210-038 // NVD: CVE-2002-1103

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1103

THREAT TYPE

network

Trust: 0.9

sources: BID: 5619 // BID: 5609 // BID: 89573

TYPE

Unknown

Trust: 0.9

sources: BID: 5609 // CNNVD: CNNVD-200210-038

EXTERNAL IDS

db:CERT/CCid:VU#761651

Trust: 2.8

db:NVDid:CVE-2002-1103

Trust: 2.0

db:BIDid:5619

Trust: 1.1

db:BIDid:5609

Trust: 1.1

db:CNNVDid:CNNVD-200210-038

Trust: 0.7

db:CISCOid:20020903 CISCO VPN 3000 CONCENTRATOR MULTIPLE VULNERABILITIES

Trust: 0.6

db:BIDid:89573

Trust: 0.4

db:VULHUBid:VHN-5491

Trust: 0.1

sources: CERT/CC: VU#761651 // VULHUB: VHN-5491 // BID: 5619 // BID: 5609 // BID: 89573 // CNNVD: CNNVD-200210-038 // NVD: CVE-2002-1103

REFERENCES

url:http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

Trust: 2.8

url:http://www.kb.cert.org/vuls/id/761651

Trust: 2.0

url:http://www.ietf.org/rfc/rfc2401.txt

Trust: 0.8

url:http://www.ietf.org/rfc/rfc2408.txt

Trust: 0.8

url:http://online.securityfocus.com/bid/5609

Trust: 0.8

url:http://online.securityfocus.com/bid/5619

Trust: 0.8

url:http://online.securityfocus.com/archive/82/292506/2002-09-13/2002-09-19/0

Trust: 0.8

url:http://www.iss.net/security_center/static/10028.php

Trust: 0.8

sources: CERT/CC: VU#761651 // VULHUB: VHN-5491 // BID: 89573 // CNNVD: CNNVD-200210-038 // NVD: CVE-2002-1103

CREDITS

Vulnerability announced in a Cisco Security Advisory.

Trust: 0.6

sources: BID: 5619 // BID: 5609

SOURCES

db:CERT/CCid:VU#761651
db:VULHUBid:VHN-5491
db:BIDid:5619
db:BIDid:5609
db:BIDid:89573
db:CNNVDid:CNNVD-200210-038
db:NVDid:CVE-2002-1103

LAST UPDATE DATE

2024-08-14T14:16:19.312000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#761651date:2002-11-14T00:00:00
db:VULHUBid:VHN-5491date:2018-10-30T00:00:00
db:BIDid:5619date:2002-09-03T00:00:00
db:BIDid:5609date:2002-09-03T00:00:00
db:BIDid:89573date:2002-10-04T00:00:00
db:CNNVDid:CNNVD-200210-038date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1103date:2018-10-30T16:26:19.107

SOURCES RELEASE DATE

db:CERT/CCid:VU#761651date:2002-09-03T00:00:00
db:VULHUBid:VHN-5491date:2002-10-04T00:00:00
db:BIDid:5619date:2002-09-03T00:00:00
db:BIDid:5609date:2002-09-03T00:00:00
db:BIDid:89573date:2002-10-04T00:00:00
db:CNNVDid:CNNVD-200210-038date:2002-10-04T00:00:00
db:NVDid:CVE-2002-1103date:2002-10-04T04:00:00