CVE-2002-0852
published 2002-09-05CVE-2002-0852: Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.30%
67.1th percentile
Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco VPN Client Multiple Vulnerabilities
vendor_cisco·2002-08-12
CVE-2002-0852 CWE-119 Cisco VPN Client Multiple Vulnerabilities
Cisco VPN Client Multiple Vulnerabilities
Multiple vulnerabilities exist in the Cisco Virtual Private Network
(VPN) Client software. Exploitation of these vulnerabilities prevents the Cisco
VPN Client software program from functioning correctly.
These vulnerabilities are documented as Cisco bug ID CSCdy26045. There
are no workarounds available to mitigate the effects of these vulnerabilities.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020812-vpnclient-vulnerability.
Cisco
Cisco VPN Client Multiple Vulnerabilities
vendor_cisco
CVE-2002-0852 Cisco VPN Client Multiple Vulnerabilities
CVE-2002-0852: Cisco VPN Client Multiple Vulnerabilities
Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) Client software. Exploitation of these vulnerabilities prevents the Cisco VPN Client software program from functioning correctly. These vulnerabilities are documented as Cisco bug ID CSCdy26045. There are no
CWE: CWE-119, CWE-119
Bug IDs: CSCdy26045, CSCdy26045, CSCdy26045
GHSA
GHSA-6x9q-xfp2-gxg6: Buffer overflows in Cisco Virtual Private Network (VPN) Client 3
ghsa_unreviewed·2022-04-30
CVE-2002-0852 [MEDIUM] GHSA-6x9q-xfp2-gxg6: Buffer overflows in Cisco Virtual Private Network (VPN) Client 3
Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2002-09-05
Published