CVE-2002-1092
Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- cisco/vpn 3000 concentrator series software
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlVendor Advisory
- http://www.securityfocus.com/bid/5613Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10017
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlVendor Advisory
- http://www.securityfocus.com/bid/5613Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10017
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.