Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-4354


The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.


Published

2010-11-30T22:14:00.913

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware cisco asa_5500 * Yes
Hardware cisco pix_500 * Yes
Hardware cisco vpn_3000_concentrator * Yes
Hardware cisco vpn_3005_concentrator * Yes
Hardware cisco vpn_3015_concentrator * Yes
Hardware cisco vpn_3020_concentrator * Yes
Hardware cisco vpn_3030_concentator * Yes
Hardware cisco vpn_3060_concentrator * Yes
Hardware cisco vpn_3080_concentrator * Yes

References