Vulnerability Name: | CVE-2002-2139 (CCN-10660) | ||||||||
Assigned: | 2002-11-20 | ||||||||
Published: | 2002-11-20 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-2139 Source: CCN Type: CIAC Information Bulletin N-017 Cisco PIX Multiple Vulnerabilities Source: CIAC Type: Patch N-017 Source: CCN Type: Cisco Systems Inc. Security Advisory, 2002 November 20 1600 UTC (GMT) Cisco PIX Multiple Vulnerabilities Source: CISCO Type: UNKNOWN 20021120 Cisco PIX Multiple Vulnerabilities Source: XF Type: UNKNOWN cisco-pix-isakmp-sa-mitm(10660) Source: CCN Type: OSVDB ID: 60069 Cisco PIX Firewall User VPN Session Duplicate ISAKMP SA MiTM Weakness Source: BID Type: Patch 6211 Source: CCN Type: BID-6211 Cisco PIX VPN Session Hijacking Vulnerability Source: XF Type: UNKNOWN cisco-pix-isakmp-sa-mitm(10660) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |