PT-2002-2095 · Cisco · Cisco Vpn 3000 Concentrator

Publicado

2002-10-04

·

Atualizado

2018-10-30

·

CVE-2002-1092

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Cisco VPN 3000 Concentrator versions 3.6(Rel) and earlier Cisco VPN 3000 Concentrator versions 2.x.x
Description: The issue allows remote VPN clients to log in using PPTP or IPSEC user authentication when the device is configured to use internal authentication with group accounts and without any user accounts.
Recommendations: For Cisco VPN 3000 Concentrator versions 3.6(Rel) and earlier, consider reconfiguring the device to include user accounts or to use an alternative authentication method. For Cisco VPN 3000 Concentrator versions 2.x.x, consider reconfiguring the device to include user accounts or to use an alternative authentication method. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1092

Produtos afetados

Cisco Vpn 3000 Concentrator