CVE-2002-1099: Medium severity Cisco Vpn 3000 Concentrator Series Software vulnerability
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1099?
CVE-2002-1099 is considered a high severity vulnerability as it allows remote attackers to access potentially sensitive information without authentication.
How do I fix CVE-2002-1099?
To mitigate CVE-2002-1099, upgrade the Cisco VPN 3000 Concentrator to version 3.5.3 or later.
Which Cisco products are affected by CVE-2002-1099?
CVE-2002-1099 affects Cisco VPN 3000 Concentrator versions 2.2.x and 3.x prior to 3.5.3.
Can CVE-2002-1099 lead to data leakage?
Yes, CVE-2002-1099 can lead to data leakage as it allows unauthorized access to sensitive HTML pages.
What type of attack does CVE-2002-1099 enable?
CVE-2002-1099 enables an information disclosure attack where attackers can retrieve sensitive information without authentication.