VulnerabilityModified
CVE-2002-1097
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
HIGH 7.5EPSS 1.13%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- cisco/vpn 3000 concentrator series software · cisco/vpn 3002 hardware client
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlVendor Advisory
- http://www.iss.net/security_center/static/10022.phpVendor Advisory
- http://www.securityfocus.com/bid/5612
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlVendor Advisory
- http://www.iss.net/security_center/static/10022.phpVendor Advisory
- http://www.securityfocus.com/bid/5612
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.