CVE-2003-0258: High severity Cisco Vpn 3015 Concentrator vulnerability
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable IPSec over TCP for any port on the concentrator; do not enable IPSec over TCP on Cisco VPN 3000 series concentrators or Cisco VPN 3002 Hardware Client to prevent remote attackers from reaching the private network without authentication.
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client IPSec over TCP = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0258?
CVE-2003-0258 has been classified with a high severity due to the potential for remote attackers to access the private network without authentication.
How do I fix CVE-2003-0258?
To fix CVE-2003-0258, ensure that IPSec over TCP is disabled on affected Cisco VPN 3000 series concentrators and update to the latest secured software version.
Which Cisco products are affected by CVE-2003-0258?
CVE-2003-0258 affects several Cisco products including the VPN 3015, 3030, 3060, 3080 Concentrators, and the VPN 3002 Hardware Client.
Can CVE-2003-0258 be exploited remotely?
Yes, CVE-2003-0258 can be exploited remotely by attackers if the vulnerability's conditions are met.
Is there a patch available for CVE-2003-0258?
Yes, Cisco provides patches in the updated versions of their VPN software that address the vulnerability known as CVE-2003-0258.