Cisco Vpn 3000 Concentrator Series Software vulnerabilities

24 known vulnerabilities affecting cisco/vpn_3000_concentrator_series_software.

Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM16LOW1

Vulnerabilities

Page 1 of 2
CVE-2006-4313MEDIUMCVSS 5.0v4.0v4.0.1+9 more2006-08-23
CVE-2006-4313 [MEDIUM] CVE-2006-4313: Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors.
nvd
CVE-2006-3906MEDIUMCVSS 5.0v2.0v2.5.2.a+46 more2006-07-27
CVE-2006-3906 [MEDIUM] CVE-2006-3906: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protoc
nvd
CVE-2006-3073LOWCVSS 2.6v2.0v2.5.2.a+33 more2006-06-19
CVE-2006-3073 [LOW] CVE-2006-3073: Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Seri Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html and (2) connecterror.html, aka bugid CSCsd810
nvd
CVE-2006-0483HIGHCVSS 7.8v4.7v4.7\(rel\)+4 more2006-01-31
CVE-2006-0483 [HIGH] CVE-2006-0483: Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.
nvd
CVE-2005-4499HIGHCVSS 7.5v2.0v2.5.2.a+39 more2005-12-22
CVE-2005-4499 [HIGH] CVE-2005-4499: The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL o The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS s
nvd
CVE-2005-3669MEDIUMCVSS 5.0v2.0v2.5.2.a+31 more2005-11-18
CVE-2005-3669 [MEDIUM] CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear whic
nvd
CVE-2005-2025MEDIUMCVSS 5.0v2.0v2.5.2.a+35 more2005-06-20
CVE-2005-2025 [MEDIUM] CVE-2005-2025: Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.
nvd
CVE-2005-0943MEDIUMCVSS 5.0v2.0v2.5.2.a+36 more2005-03-30
CVE-2005-0943 [MEDIUM] CVE-2005-0943: Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to c Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.
nvd
CVE-2003-0258HIGHCVSS 7.5v3.5\(rel\)v3.5.1+15 more2003-05-27
CVE-2003-0258 [HIGH] CVE-2003-0258: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when e Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.
nvd
CVE-2003-0260MEDIUMCVSS 5.0v2.0v2.5.2.a+24 more2003-05-27
CVE-2003-0260 [MEDIUM] CVE-2003-0260: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow re Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
nvd
CVE-2003-0259MEDIUMCVSS 5.0v2.0v2.5.2.a+29 more2003-05-27
CVE-2003-0259 [MEDIUM] CVE-2003-0259: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows re Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.
nvd
CVE-2002-1096HIGHCVSS 7.5v2.0v2.5.2.a+14 more2002-10-04
CVE-2002-1096 [HIGH] CVE-2002-1096: Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.
nvd
CVE-2002-1098HIGHCVSS 7.5v2.0v2.5.2.a+17 more2002-10-04
CVE-2002-1098 [HIGH] CVE-2002-1098: Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto) Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.
nvd
CVE-2002-1097HIGHCVSS 7.5v2.0v2.5.2.a+14 more2002-10-04
CVE-2002-1097 [HIGH] CVE-2002-1097: Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
nvd
CVE-2002-1092HIGHCVSS 7.5≤ 3.6\(rel\)2002-10-04
CVE-2002-1092 [HIGH] CVE-2002-1092: Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authent Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.
nvd
CVE-2002-1101MEDIUMCVSS 5.0PoCv2.0v2.5.2.a+20 more2002-10-04
CVE-2002-1101 [MEDIUM] CVE-2002-1101: Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.
nvd
CVE-2002-1103MEDIUMCVSS 5.0v2.0v2.5.2.a+20 more2002-10-04
CVE-2002-1103 [MEDIUM] CVE-2002-1103: Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.
nvd
CVE-2002-1094MEDIUMCVSS 5.0v2.0v2.5.2.a+17 more2002-10-04
CVE-2002-1094 [MEDIUM] CVE-2002-1094: Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.
nvd
CVE-2002-1102MEDIUMCVSS 5.0v2.0v2.5.2.a+18 more2002-10-04
CVE-2002-1102 [MEDIUM] CVE-2002-1102: The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.
nvd
CVE-2002-1095MEDIUMCVSS 5.0v2.0v2.5.2.a+3 more2002-10-04
CVE-2002-1095 [MEDIUM] CVE-2002-1095: Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cau Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
nvd