HIGH · 7.5

CVE-2002-1092

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using...

Vulnerability Description

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoVpn 3000 Concentrator Series Software<= 3.6\(rel\)

References

FAQ

What is CVE-2002-1092?

CVE-2002-1092 is a vulnerability with a CVSS score of 7.5 (HIGH). Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using...

How severe is CVE-2002-1092?

CVE-2002-1092 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1092?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Vpn 3000 Concentrator Series Software.