Vulnerability Name: | CVE-2010-4354 (CCN-21072) | ||||||||
Assigned: | 2005-06-20 | ||||||||
Published: | 2005-06-20 | ||||||||
Updated: | 2010-12-01 | ||||||||
Summary: | The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2025 Source: MITRE Type: CNA CVE-2010-4354 Source: CCN Type: SA42414 Cisco IPsec VPN Implementation Group Name Enumeration Weakness Source: CCN Type: Cisco Security Response Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability Source: CISCO Type: Vendor Advisory 20101129 Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability Source: CCN Type: NTA Monitor Security Advisory Cisco VPN Concentrator Groupname Enumeration Vulnerability Source: CCN Type: OSVDB ID: 17405 Cisco VPN Concentrator Group Name Enumeration Source: CCN Type: OSVDB ID: 69582 Cisco Multiple Products IPSec VPN Aggressive Mode IKE Phase I Message Response Group Name Remote Enumeration Source: CCN Type: BID-13992 Cisco VPN Concentrator Groupname Enumeration Weakness Source: CCN Type: BID-45161 Cisco IPSec VPN Groupname Enumeration Weakness Source: XF Type: UNKNOWN cisco-groupname-disclosure(21072) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |