cbcvebase.
CVE-2005-2025
published 2005-06-20

CVE-2005-2025: Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in…

medium5CVSS 3.1
AVNACLAuNCPINAN
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
cisa9.8CRITICAL