CVE-2002-1106
Published Oct 4, 2002
Last updated 7 years ago
Overview
- Description
- Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "398B68C7-C1DB-4A62-B0A2-89C917768E58" }, { "criteria": "cpe:2.3:a:cisco:vpn_client:3.0:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20C66C87-1367-4440-A2C2-E6B657DA2743" }, { "criteria": "cpe:2.3:a:cisco:vpn_client:3.1:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A270D7C-ACBC-41A4-A606-8A4F35894E74" }, { "criteria": "cpe:2.3:a:cisco:vpn_client:3.5.1:*:windows:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59938F7D-5F64-4FC0-A5B2-C798AF297130" } ], "operator": "OR" } ] } ]