CVE-2002-1095: Medium severity Cisco Vpn 3000 Concentrator Series Software vulnerability
Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1095?
CVE-2002-1095 is classified as a denial of service vulnerability that can significantly disrupt Cisco VPN 3000 Concentrators.
How does CVE-2002-1095 work?
CVE-2002-1095 allows remote attackers to trigger a reload of the Cisco VPN 3000 Concentrator by exploiting the 'No Encryption' option in a Windows-based PPTP client.
What versions are affected by CVE-2002-1095?
CVE-2002-1095 affects Cisco VPN 3000 Concentrator versions prior to 2.5.2(F) with encryption enabled.
How can organizations mitigate CVE-2002-1095?
Organizations can mitigate CVE-2002-1095 by upgrading their Cisco VPN 3000 Concentrator to version 2.5.2(F) or later.
Are there any workarounds for CVE-2002-1095?
A potential workaround for CVE-2002-1095 is to disable the use of the 'No Encryption' option in PPTP clients connecting to the Cisco VPN 3000 Concentrator.