PT-2001-1642 · Cisco · Cisco Vpn 3000 Series Concentrators

Publicado

2001-06-18

·

Atualizado

2017-10-10

·

CVE-2001-0427

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco VPN 3000 series concentrators versions prior to 2.5.2(F)
Description The issue allows remote attackers to cause a denial of service via a flood of invalid login requests to the SSL service or the telnet service. These services do not properly disconnect the user after several failed login attempts.
Recommendations For versions prior to 2.5.2(F), update to version 2.5.2(F) or later to resolve the issue. As a temporary workaround, consider restricting access to the SSL and telnet services to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2001-0427

Produtos afetados

Cisco Vpn 3000 Series Concentrators