Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
2001-06-18T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:N/A:C
8.6
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | cisco | vpn_3000_concentrator | * | Yes |
Hardware | cisco | vpn_3005_concentrator | * | Yes |
Hardware | cisco | vpn_3015_concentrator | * | Yes |
Hardware | cisco | vpn_3030_concentator | * | Yes |
Hardware | cisco | vpn_3060_concentrator | * | Yes |
Hardware | cisco | vpn_3080_concentrator | * | Yes |