SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-0427

Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several…

HIGH 7.1EPSS 2.52%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.

CVSS 2.0
7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS
2.52% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cisco/vpn 3000 concentrator · cisco/vpn 3005 concentrator · cisco/vpn 3015 concentrator · cisco/vpn 3030 concentator · cisco/vpn 3060 concentrator · cisco/vpn 3080 concentrator
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.