PT-2002-2101 · Cisco · Cisco Vpn 3000 Concentrator
Published
2002-10-04
·
Updated
2018-10-30
·
CVE-2002-1098
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Cisco VPN 3000 Concentrator versions 2.2.x through 3.x before 3.5.3
Description:
The issue allows arbitrary traffic to pass through the concentrator due to a misconfiguration when the XML filter configuration is enabled. This occurs because the protocol is set to "ANY" when the "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule is added.
Recommendations:
For versions 2.2.x through 3.x before 3.5.3, update to version 3.5.3 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Vpn 3000 Concentrator