Page 2 of 7 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 23EXPL: 0

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication. Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 4.0.REL, cuando se configuran para permitir IPSec sobre TCP para un puerto del concentrador, permiten que atacantes remotos alcancen la red privada sin autentificación. • http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml http://www.kb.cert.org/vuls/id/727780 https://exchange.xforce.ibmcloud.com/vulnerabilities/11954 •

CVSS: 7.1EPSS: 0%CPEs: 6EXPL: 0

Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts. • http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml http://www.osvdb.org/5643 https://exchange.xforce.ibmcloud.com/vulnerabilities/6298 • CWE-20: Improper Input Validation •