Vulnerabilities > Cisco > VPN 3000 Concentrator Series Software > 2.5.2.d

DATE CVE VULNERABILITY TITLE RISK
2006-06-19 CVE-2006-3073 Cross-Site Scripting vulnerability in Cisco VPN3K/ASA WebVPN Clientless Mode
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html and (2) connecterror.html, aka bugid CSCsd81095 (VPN3k) and CSCse48193 (ASA).
network
high complexity
cisco
2.6
2005-06-20 CVE-2005-2025 Unspecified vulnerability in Cisco products
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.
network
low complexity
cisco
5.0
2005-03-30 CVE-2005-0943 Remote Denial of Service vulnerability in Cisco VPN 3000 Concentrator
Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.
network
low complexity
cisco
5.0
2003-05-27 CVE-2003-0260 Denial-Of-Service vulnerability in VPN 3000 Concentrator
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
network
low complexity
cisco
5.0
2003-05-27 CVE-2003-0259 Denial-Of-Service vulnerability in VPN 3000 Concentrator
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.
network
low complexity
cisco
5.0
2002-10-04 CVE-2002-1103 Denial-Of-Service vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.
network
low complexity
cisco
5.0
2002-10-04 CVE-2002-1102 Denial of Service vulnerability in Cisco products
The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.
network
low complexity
cisco
5.0
2002-10-04 CVE-2002-1101 Denial-Of-Service vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.
network
low complexity
cisco
5.0
2002-10-04 CVE-2002-1100 Denial Of Service vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.
network
low complexity
cisco
5.0
2002-10-04 CVE-2002-1099 Information Disclosure vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.
network
low complexity
cisco
5.0