CVE-2001-0427
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/vpn 3000 concentrator · cisco/vpn 3005 concentrator · cisco/vpn 3015 concentrator · cisco/vpn 3030 concentator · cisco/vpn 3060 concentrator · cisco/vpn 3080 concentrator
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/5643
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6298
- http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/5643
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6298
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.