CVE-2005-2025: Medium severity Cisco VPN 3000 Concentrator vulnerability
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2025?
CVE-2005-2025 has a medium severity level due to its ability to disclose valid groupnames to remote attackers.
How do I fix CVE-2005-2025?
To fix CVE-2005-2025, upgrade the Cisco VPN 3000 Concentrator to version 4.1.7 or later.
What are the affected Cisco products for CVE-2005-2025?
The affected products include various models of Cisco VPN 3000 Concentrator series and the Cisco VPN 3005 Concentrator.
Can CVE-2005-2025 be exploited remotely?
Yes, CVE-2005-2025 can be exploited remotely by attackers sending crafted IKE packets.
What impact does CVE-2005-2025 have on Cisco's VPN 3000 devices?
CVE-2005-2025 allows attackers to determine valid groupnames, potentially leading to further attacks.