CVE-2003-0260
published 2003-05-27CVE-2003-0260: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.13%
79.8th percentile
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn_3000_concentrator | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco VPN 3000 Concentrator Vulnerabilities
vendor_cisco·2003-05-07
CVE-2003-0258 Cisco VPN 3000 Concentrator Vulnerabilities
Cisco VPN 3000 Concentrator Vulnerabilities
This advisory documents vulnerabilities for the Cisco VPN 3000 series
concentrators and Cisco VPN 3002 Hardware Client. These vulnerabilities are
documented as Cisco bug ID CSCea77143 (IPSec over TCP), CSCdz15393 (SSH), and
CSCdt84906 (ICMP). There are workarounds available to mitigate the effects of
these vulnerabilities. Upgrading to the latest version of code for the Cisco
VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client, version 4.0.1
and 3.6.7F, would protect against all of these documented vulnerabilities.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20030507-vpn3k.
Cisco
Cisco VPN 3000 Concentrator Vulnerabilities
vendor_cisco
CVE-2003-0260 Cisco VPN 3000 Concentrator Vulnerabilities
CVE-2003-0260: Cisco VPN 3000 Concentrator Vulnerabilities
This advisory documents vulnerabilities for the Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client. These vulnerabilities are documented as Cisco bug ID CSCea77143 (IPSec over TCP), CSCdz15393 (SSH), and CSCdt84906 (ICMP). There are
Bug IDs: CSCea77143, CSCdz15393, CSCdt84906, CSCea77143, CSCdz15393
GHSA
GHSA-mph8-9gj5-mgrr: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2
ghsa_unreviewed·2022-04-29
CVE-2003-0260 [MEDIUM] GHSA-mph8-9gj5-mgrr: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
blogs_talos·2014-01-14·CVSS 9.8
CVE-2014-0258 [CRITICAL] Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
The first Microsoft Update Tuesday of 2014 is here and it’s a very light month this time around. We’ve got 4 bulletins covering 6 CVEs. What’s remarkable is that there’s no Internet Explorer bulletin this month. There are also no bulletins that are marked critical, all 4 bulletins are marked as important.
The first bulletin, MS14-001, is for Word and Office Web Apps, this bulletin covers 3 CVEs (CVE-2014-0258, CVE-2014-0259 and CVE-2014-0260. They are memory corruption vulnerabilities in Word, which could result in remote code execution.
MS14-002 is a fix for the Windows XP/2003 0-day kernel escalation of privilege vulnerability (CVE-2013-5065) that was being exploited in the wild in tandem with the Adobe Reader vulnerability (CVE-2013-3346). Here an attacker would convince the user to o
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
blogs_talos·2014-01-14·CVSS 9.8
CVE-2014-0258 [CRITICAL] Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
## Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
The first Microsoft Update Tuesday of 2014 is here and it’s a very light month this time around. We’ve got 4 bulletins covering 6 CVEs. What’s remarkable is that there’s no Internet Explorer bulletin this month. There are also no bulletins that are marked critical, all 4 bulletins are marked as important.
The first bulletin, MS14-001 , is for Word and Office Web Apps, this bulletin covers 3 CVEs ( CVE-2014-0258 , CVE-2014-0259 and CVE-2014-0260 . They are memory corruption vulnerabilities in Word, which could result in remote code execution.
MS14-002 is a fix for the Windows XP/2003 0-day kernel escalation of privilege vulnerability ( CVE-2013-5065 ) that was being exploited in the wild in tandem with the
http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtmlhttp://www.kb.cert.org/vuls/id/221164https://exchange.xforce.ibmcloud.com/vulnerabilities/11956http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtmlhttp://www.kb.cert.org/vuls/id/221164https://exchange.xforce.ibmcloud.com/vulnerabilities/11956
2003-05-27
Published