CVE-2002-1100
published 2002-10-04CVE-2002-1100: Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.66%
73.9th percentile
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Trend Micro PC-cillin 2000/2002/2003 - Mail Scanner Buffer Overflow
exploitdb·2002-12-10
CVE-2002-1349 Trend Micro PC-cillin 2000/2002/2003 - Mail Scanner Buffer Overflow
Trend Micro PC-cillin 2000/2002/2003 - Mail Scanner Buffer Overflow
---
source: https://www.securityfocus.com/bid/6350/info
A buffer overflow vulnerability has been reported for PC-cillin's mail scanning utility.
An attacker can exploit this vulnerability by connecting to a vulnerable pop3trap.exe service and sending an overly long string. This will result in the process crashing and allowing the attacker to gain control over the execution of the process.
#!/usr/bin/perl
#pc-cillin DOS..will add shellcode l8r..
use IO::Socket;
$buf = 1100;
$host = $ARGV[0];
$port = $ARGV[1];
#shellcode needs to be modded..
#return addr is in the shellcode; doesn't work? go figure..
$hellcode = "\xF0\x00\x00\x00\x58\x55\x89\xE5\x81\xEC\x2C\x00\x00\x00\x89\x45\xD4\xC7\x45\xFC".
"\x00\x00\xE7\x77\x8B
Exploit-DB
Telindus 1100 Series Router - Administration Password Leak
exploitdb·2002-06-05
CVE-2002-0949 Telindus 1100 Series Router - Administration Password Leak
Telindus 1100 Series Router - Administration Password Leak
---
// source: https://www.securityfocus.com/bid/4946/info
The 1100 series routers are a broadband connectivity solution distributed by Telindus.
Under some circumstances, a vulnerable Telindus router may leak sensitive information. When an attempt to connect to the router is made using the administrative software, the router sends the password to the client in plain text. This packet is sent via UDP.
**The vendor has released firmware version 6.0.27, dated July 2002. Reports suggest that this firmware does not adequately protect against this vulnerability. The firmware is reported to use an encrypted UDP packet when connecting to the router. However, the firmware uses a weak encryption scheme and thus it is easily circumvente
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlhttp://www.iss.net/security_center/static/10025.phphttp://www.securityfocus.com/bid/5617http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtmlhttp://www.iss.net/security_center/static/10025.phphttp://www.securityfocus.com/bid/5617
2002-10-04
Published