First published: Mon Jul 02 2001(Updated: )
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco VPN 3000 concentrator series software | =2.5.2.a | |
Cisco VPN 3000 concentrator series software | =2.5.2.b | |
Cisco VPN 3000 concentrator series software | =2.5.2.c | |
Cisco VPN 3000 concentrator series software | =2.5.2.d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0428 is classified as a denial of service vulnerability that can severely disrupt the functionality of affected Cisco VPN 3000 series concentrators.
To resolve CVE-2001-0428, users should upgrade their Cisco VPN 3000 series concentrators to version 2.5.2(F) or later.
CVE-2001-0428 affects all versions prior to 2.5.2(F) of the Cisco VPN 3000 series concentrators.
Currently, the recommended solution is to apply the necessary software update; no specific workarounds are provided for CVE-2001-0428.
CVE-2001-0428 can potentially be exploited by remote attackers targeting unpatched Cisco VPN 3000 series concentrators.