PT-2002-2101 · Cisco · Cisco Vpn 3000 Concentrator

Published

2002-10-04

·

Updated

2018-10-30

·

CVE-2002-1098

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Cisco VPN 3000 Concentrator versions 2.2.x through 3.x before 3.5.3
Description: The issue allows arbitrary traffic to pass through the concentrator due to a misconfiguration when the XML filter configuration is enabled. This occurs because the protocol is set to "ANY" when the "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule is added.
Recommendations: For versions 2.2.x through 3.x before 3.5.3, update to version 3.5.3 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1098

Affected Products

Cisco Vpn 3000 Concentrator