CVE-2001-0427: Input Validation
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0427?
CVE-2001-0427 is considered a denial of service vulnerability that can disrupt availability by allowing remote attackers to flood the system with invalid login requests.
How do I fix CVE-2001-0427?
To mitigate CVE-2001-0427, it is recommended to upgrade to Cisco VPN 3000 series concentrators firmware version 2.5.2(F) or later.
What products are affected by CVE-2001-0427?
CVE-2001-0427 affects several models of Cisco VPN 3000 series concentrators including the 3015, 3060, 3000, 3005, 3030, and 3080.
Can CVE-2001-0427 be exploited internally?
Yes, CVE-2001-0427 can be exploited by internal attackers if they can send a flood of invalid login requests to the vulnerable services.
Is CVE-2001-0427 a patchable vulnerability?
Yes, CVE-2001-0427 can be mitigated by applying the recommended firmware updates provided by Cisco.