Lucene search

K
cveMitreCVE-2002-1092
HistorySep 01, 2004 - 4:00 a.m.

CVE-2002-1092

2004-09-0104:00:00
mitre
web.nvd.nist.gov
21
cisco
vpn
concentrator
authentication
pptp
ipsec
vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

74.5%

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

Affected configurations

Nvd
Node
ciscovpn_3000_concentrator_series_softwareRange3.6\(rel\)
VendorProductVersionCPE
ciscovpn_3000_concentrator_series_software*cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

74.5%

Related for CVE-2002-1092