CVE-2002-1108

3 documents3 sources
Severity
5.0MEDIUM
EPSS
0.4%
top 39.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateApr 30

Description

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/vpn_client6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-mvq9-7wg5-rmxc: Cisco Virtual Private Network (VPN) Client software 22022-04-30
CVEList
CVE-2002-1108: Cisco Virtual Private Network (VPN) Client software 22004-09-01