CVE-2002-1104: Medium severity Cisco VPN Client vulnerability
Published Oct 4, 2002
·Updated
Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).
Affected Software
2 affected components
Cisco VPN Client=3.0
Cisco VPN Client=2.0
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1104?
CVE-2002-1104 has a severity rating of high due to its potential to cause a denial of service.
2
How do I fix CVE-2002-1104?
To fix CVE-2002-1104, upgrade the Cisco VPN Client software to version 3.0.5 or later.
3
Who is affected by CVE-2002-1104?
CVE-2002-1104 affects users running Cisco VPN Client versions 2.x.x and 3.x up to 3.0.4 on Windows.
4
What type of attack does CVE-2002-1104 allow?
CVE-2002-1104 allows remote attackers to cause a denial of service by sending malicious TCP packets.
5
What is the context of CVE-2002-1104?
CVE-2002-1104 is specifically related to vulnerabilities in Cisco VPN Client that can lead to crashes when certain TCP packets are received.