VulnerabilityModified
CVE-2002-1108
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.
MEDIUM 5.0EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- cisco/vpn client
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/vpnclient-multiple2-vuln-pub.shtmlVendor Advisory
- http://www.securityfocus.com/bid/5651Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10047
- http://www.cisco.com/warp/public/707/vpnclient-multiple2-vuln-pub.shtmlVendor Advisory
- http://www.securityfocus.com/bid/5651Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10047
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.