CVE-2003-0258

6 documents5 sources
Severity
7.5HIGH
EPSS
2.3%
top 15.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateApr 29

Description

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jv37-pvx6-rjx4: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 32022-04-29
CVEList
CVE-2003-0258: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 32003-05-08

📋Vendor Advisories

1
Cisco
Cisco VPN 3000 Concentrator Vulnerabilities2003-05-07

🕵️Threat Intelligence

2
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14