Vulnerability Name: | CVE-2001-0427 (CCN-6298) | ||||||||
Assigned: | 2001-03-28 | ||||||||
Published: | 2001-03-28 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2001-0427 Source: CCN Type: CIAC Information Bulletin L-068 Cisco VPN3000 Concentrator TELNET Vulnerability Source: CCN Type: Cisco Systems Field Notice, March 28, 2001 VPN3000 Concentrator TELNET Vulnerability Source: CISCO Type: Patch, Vendor Advisory 20010328 VPN3000 Concentrator TELNET Vulnerability Source: OSVDB Type: UNKNOWN 5643 Source: CCN Type: OSVDB ID: 5643 Cisco VPN Concentrator Invalid Login DoS Source: XF Type: UNKNOWN cisco-vpn-telnet-dos(6298) Source: XF Type: UNKNOWN cisco-vpn-telnet-dos(6298) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |