Overview
Cisco VPN 3000 series concentrators do not properly handle specially crafted Internet Security Association and Key Management Protocol (ISAKMP) packets, which can cause a vulnerable device to reload, denying service to legitimate users.
Description
According to information on the Cisco web site, The Cisco VPN 3000 Series Concentrators are a family of purpose-built, remote access Virtual Private Network (VPN) platforms and client software that incorporates high availability, high performance and scalability with the most advanced encryption and authentication techniques available today. |
Impact
An unauthenticated, remote attacker can cause a vulnerable device to reload by sending specially crafted ISAKMP packets to port 500/udp. |
Solution
|
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
- http://www.ietf.org/rfc/rfc2401.txt
- http://www.ietf.org/rfc/rfc2408.txt
- http://online.securityfocus.com/bid/5609
- http://online.securityfocus.com/bid/5619
- http://online.securityfocus.com/archive/82/292506/2002-09-13/2002-09-19/0
- http://www.iss.net/security_center/static/10028.php
Acknowledgements
The CERT/CC thanks Phenoelit for reporting this vulnerability and Cisco for information used in this document.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2002-1103 |
Severity Metric: | 7.73 |
Date Public: | 2002-09-03 |
Date First Published: | 2002-09-03 |
Date Last Updated: | 2002-11-14 05:04 UTC |
Document Revision: | 22 |