Vulnerabilities > CVE-2002-1095 - Remote Denial Of Service vulnerability in Cisco products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
cisco
nessus

Summary

Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.

Nessus

  • NASL familyCISCO
    NASL idCSCDT56514.NASL
    descriptionThe remote VPN concentrator is vulnerable to an internal PPTP / IPSEC authentication login attack. This vulnerability is documented as Cisco bug ID CSCdt56514.
    last seen2020-06-01
    modified2020-06-02
    plugin id11287
    published2003-03-01
    reporterThis script is (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11287
    titleCisco VPN 3000 Concentrator Multiple Vulnerabilities (CSCdt56514, CSCdv66718)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    #
    # Thanks to Nicolas FISCHBACH ([email protected]) for his help
    #
    
    
    include("compat.inc");
    
    if(description)
    {
     script_id(11287);
     script_bugtraq_id(5613);
     script_version("1.21");
     script_cve_id("CVE-2002-1092","CVE-2002-1095");
    
     script_name(english:"Cisco VPN 3000 Concentrator Multiple Vulnerabilities (CSCdt56514, CSCdv66718)");
    
     script_set_attribute(attribute:"synopsis", value:
    "The remote device is missing a vendor-supplied security patch." );
     script_set_attribute(attribute:"description", value:
    "The remote VPN concentrator is vulnerable to an internal PPTP / IPSEC
    authentication login attack. 
    
    This vulnerability is documented as Cisco bug ID CSCdt56514." );
     script_set_attribute(attribute:"solution", value:
    "http://www.nessus.org/u?d2dd6759" );
     script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P");
     script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
     script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
     script_set_attribute(attribute:"exploit_available", value:"false");
    
     script_set_attribute(attribute:"plugin_publication_date", value: "2003/03/01");
     script_set_attribute(attribute:"vuln_publication_date", value: "2002/09/03");
     script_cvs_date("Date: 2018/06/27 18:42:25");
     script_set_attribute(attribute:"plugin_type", value:"local");
     script_set_attribute(attribute:"cpe", value: "cpe:/o:cisco:ios");
     script_end_attributes();
    
    
     summary["english"] = "Uses SNMP to determine if a flaw is present";
     script_summary(english:summary["english"]);
    
     script_category(ACT_GATHER_INFO);
    
     script_copyright(english:"This script is (C) 2003-2018 Tenable Network Security, Inc.");
    
     script_family(english:"CISCO");
    
     script_dependencie("snmp_sysDesc.nasl");
     script_require_keys("SNMP/community",
    			  "SNMP/sysDesc",
    			  "CISCO/model");
     exit(0);
    }
    
    
    # The code starts here
    ok=0;
    
    os = get_kb_item("SNMP/sysDesc"); if(!os)exit(0);
    
    
    
    
    # Is this a VPN3k concentrator ?
    if(!egrep(pattern:".*VPN 3000 Concentrator.*", string:os))exit(0);
    
    
    # 3.6(Rel)
    if(egrep(pattern:".*Version 3\.6\.Rel.*", string:os))ok = 1;
    
    # 3.5(Rel)
    if(egrep(pattern:".*Version 3\.5\.Rel.*", string:os))ok = 1;
    
    # 3.5.x -> 3.5.4
    if(egrep(pattern:".*Version 3\.5\.[0-4].*", string:os))ok = 1;
    
    # 3.1.x -> 3.1.2
    if(egrep(pattern:".*Version 3\.1\.Rel.*", string:os))ok = 1;
    if(egrep(pattern:".*Version 3\.1\.[0-1][^0-9].*", string:os))ok = 1;
    
    # < 3.0.3(B)
    if(egrep(pattern:".*Version 3\.0\.[0-2].*", string:os))ok = 1;
    
    # 2.x.x
    if(egrep(pattern:".*Version 2\..*", string:os))ok = 1;
    
    
    
    if(ok)security_hole(port:161, proto:"udp");
    
  • NASL familyCISCO
    NASL idCSCDX39981.NASL
    descriptionThe remote VPN concentrator is subject to a VPN client authentication vulnerability that can force a reload of the concentrator when a very large string for the username prompt is sent. This vulnerability is documented as Cisco bug ID CSCdx39981.
    last seen2020-06-01
    modified2020-06-02
    plugin id11295
    published2003-03-01
    reporterThis script is (C) 2003-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/11295
    titleCisco VPN 3000 Concentrator PPTP No Encryption Option Remote DoS (CSCdx39981)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    # Thanks to Nicolas FISCHBACH ([email protected]) for his help
    #
    # Ref:  http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020903-vpn3k-vulnerability
    
    
    include("compat.inc");
    
    if(description)
    {
     script_id(11295);
     script_version("1.20");
     script_cve_id("CVE-2002-1095");
     script_bugtraq_id(5625);
    
     script_name(english:"Cisco VPN 3000 Concentrator PPTP No Encryption Option Remote DoS (CSCdx39981)");
    
     script_set_attribute(attribute:"synopsis", value:
    "The remote device is missing a vendor-supplied security patch." );
     script_set_attribute(attribute:"description", value:
    "The remote VPN concentrator is subject to a VPN client
    authentication vulnerability that can force a reload of the
    concentrator when a very large string for the username prompt is sent.
    
    This vulnerability is documented as Cisco bug ID CSCdx39981." );
     script_set_attribute(attribute:"solution", value:
    "http://www.nessus.org/u?d2dd6759" );
     script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P");
     script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
     script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
     script_set_attribute(attribute:"exploit_available", value:"false");
    
     script_set_attribute(attribute:"plugin_publication_date", value: "2003/03/01");
     script_cvs_date("Date: 2018/06/27 18:42:25");
     script_set_attribute(attribute:"vuln_publication_date", value: "2002/09/03");
     script_set_attribute(attribute:"plugin_type", value:"local");
     script_set_attribute(attribute:"cpe", value: "cpe:/o:cisco:ios");
     script_end_attributes();
    
     script_summary(english:"Uses SNMP to determine if a flaw is present");
     script_category(ACT_GATHER_INFO);
     script_copyright(english:"This script is (C) 2003-2018 Tenable Network Security, Inc.");
     script_family(english:"CISCO");
     script_dependencie("snmp_sysDesc.nasl");
     script_require_keys("SNMP/community", "SNMP/sysDesc", "CISCO/model");
     exit(0);
    }
    
    # The code starts here
    
    ok=0;
    
    os = get_kb_item("SNMP/sysDesc"); if(!os)exit(0);
    
    # Is this a VPN3k concentrator ?
    if(!egrep(pattern:".*VPN 3000 Concentrator.*", string:os))exit(0);
    
    # 3.6.Rel
    if(egrep(pattern:".*Version 3\.6\.Rel.*", string:os))ok = 1;
    
    # < 3.5.5
    if(egrep(pattern:".*Version 3\.5\.Rel.*", string:os))ok = 1;
    if(egrep(pattern:".*Version 3\.5\.[0-4].*", string:os))ok = 1;
    
    # 3.1.x
    if(egrep(pattern:".*Version 3\.1\..*", string:os))ok = 1;
    
    # 3.0.x
    if(egrep(pattern:".*Version 3\.0\..*", string:os))ok = 1;
    
    # 2.x.x
    if(egrep(pattern:".*Version 2\..*", string:os))ok = 1;
    
    
    if(ok)security_warning(port:161, proto:"udp");