- EPSS 67.67%
- Veröffentlicht 23.08.2006 22:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify fil...
- EPSS 4.28%
- Veröffentlicht 27.07.2006 22:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the sess...
CVE-2006-3073
- EPSS 0.98%
- Veröffentlicht 19.06.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitr...
CVE-2006-0483
- EPSS 1.07%
- Veröffentlicht 31.01.2006 20:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.
CVE-2005-4499
- EPSS 1.91%
- Veröffentlicht 22.12.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, w...
- EPSS 9.46%
- Veröffentlicht 18.11.2005 21:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the...
- EPSS 0.5%
- Veröffentlicht 20.06.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate ...
- EPSS 0.74%
- Veröffentlicht 30.03.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.
- EPSS 0.66%
- Veröffentlicht 27.05.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
- EPSS 0.66%
- Veröffentlicht 27.05.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.