Vulnerabilities > CVE-2002-1102 - Unspecified vulnerability in Cisco products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cisco
nessus
Summary
The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.
Vulnerable Configurations
Nessus
NASL family | CISCO |
NASL id | CSCDX54675.NASL |
description | The remote VPN concentrator is subject to a LAN-to-LAN IPSEC tunnel vulnerability which allows remote attackers to cause a denial of service. Existing associations might be removed when a new connection is made and no check is done in order to determine if the connection comes from the proper network. This vulnerability is documented as Cisco bug ID CSCdx54675 |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11296 |
published | 2003-03-01 |
reporter | This script is (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11296 |
title | Cisco VPN 3000 Concentrator LAN-to-LAN IPSEC Tunnel Connection Termination DoS (CSCdx54675) |
code |
|
References
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
- http://www.securityfocus.com/bid/5622
- http://www.securityfocus.com/bid/5622
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10027