First published: Fri Oct 04 2002(Updated: )
The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco VPN 3000 concentrator series software | =2.0 | |
Cisco VPN 3000 concentrator series software | =2.5.2.a | |
Cisco VPN 3000 concentrator series software | =2.5.2.b | |
Cisco VPN 3000 concentrator series software | =2.5.2.c | |
Cisco VPN 3000 concentrator series software | =2.5.2.d | |
Cisco VPN 3000 concentrator series software | =2.5.2.f | |
Cisco VPN 3000 concentrator series software | =3.0 | |
Cisco VPN 3000 concentrator series software | =3.0\(rel\) | |
Cisco VPN 3000 concentrator series software | =3.0.3.a | |
Cisco VPN 3000 concentrator series software | =3.0.3.b | |
Cisco VPN 3000 concentrator series software | =3.0.4 | |
Cisco VPN 3000 concentrator series software | =3.1 | |
Cisco VPN 3000 concentrator series software | =3.1\(rel\) | |
Cisco VPN 3000 concentrator series software | =3.1.1 | |
Cisco VPN 3000 concentrator series software | =3.1.2 | |
Cisco VPN 3000 concentrator series software | =3.1.4 | |
Cisco VPN 3000 concentrator series software | =3.5\(rel\) | |
Cisco VPN 3000 concentrator series software | =3.5.1 | |
Cisco VPN 3000 concentrator series software | =3.5.2 | |
Cisco VPN 3000 concentrator series software | =3.5.3 | |
Cisco VPN 3002 Hardware Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1102 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2002-1102, upgrade your Cisco VPN 3000 Concentrator software to version 3.5.4 or later.
CVE-2002-1102 affects Cisco VPN 3000 Concentrator versions 2.2.x, 2.5.x, and 3.x prior to 3.5.4.
CVE-2002-1102 enables remote attackers to execute a denial of service attack via specific LAN-to-LAN connections.
While updating the software is the best practice, implementing firewall rules to control incoming LAN-to-LAN connections can mitigate the risk.