Vulnerabilities > CVE-2002-1097 - Unspecified vulnerability in Cisco products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cisco
nessus
Summary
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
Vulnerable Configurations
Nessus
NASL family | CISCO |
NASL id | CSCDW50657.NASL |
description | The remote VPN concentrator discloses the certificate passwords of its users in the source HTML pages of the embedded web server. This vulnerability is documented as Cisco bug ID CSCdw50657. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11294 |
published | 2003-03-01 |
reporter | This script is (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11294 |
title | Cisco VPN 3000 Concentrator Certificate Management Page HTML Source Certificate Password Disclosure (CSCdw50657) |
code |
|
References
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
- http://www.iss.net/security_center/static/10022.php
- http://www.iss.net/security_center/static/10022.php
- http://www.securityfocus.com/bid/5612
- http://www.securityfocus.com/bid/5612