CVE-2010-4354
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.
La implementación del acceso remoto de IPSec VPN en las series de dispositivos Cisco Adaptive Security Appliances (ASA) 5500, PIX Security Appliances 500 , y concentradores VPN 3000 responden a un mensaje 'Aggressive Mode IKE Phase I' sólo cuando el nombre del grupo está configurado en el dispositivo, lo que permite enumerar los nombres válidos de grupo a atacantes remotos a través de una serie de intentos de negociación IKE. Este fallo también conocido como ID CSCtj96108. Se trata de una vulnerabilidad diferente a CVE-2005-2025.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-11-30 CVE Reserved
- 2010-11-30 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.cisco.com/en/US/products/products_security_response09186a0080b5992c.html | 2010-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Asa 5500 Search vendor "Cisco" for product "Asa 5500" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Pix 500 Search vendor "Cisco" for product "Pix 500" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3000 Concentrator Search vendor "Cisco" for product "Vpn 3000 Concentrator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3005 Concentrator Search vendor "Cisco" for product "Vpn 3005 Concentrator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3015 Concentrator Search vendor "Cisco" for product "Vpn 3015 Concentrator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3020 Concentrator Search vendor "Cisco" for product "Vpn 3020 Concentrator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3030 Concentator Search vendor "Cisco" for product "Vpn 3030 Concentator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3060 Concentrator Search vendor "Cisco" for product "Vpn 3060 Concentrator" | * | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Vpn 3080 Concentrator Search vendor "Cisco" for product "Vpn 3080 Concentrator" | * | - |
Affected
|