Cisco VPN 3000 Series Multiple Vulnerabilities (CSCdea77143, CSCdz15393, CSCdt84906)
|
|
Article ID: 11594
Last updated: 27 Jan, 2009
|
|
|
|
Views: 456
|
|
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.
|
|
Cisco VPN 3000 Series Multiple Vulnerabilities (CSCdea77143, CSCdz15393, CSCdt84906) |
|
| This script is (C) 2003-2009 Tenable Network Security, Inc. |
|
|
| Family | CISCO |
| Plugin ID | 11594 |
| Bugtraq ID |
|
| CVE ID | CVE-2003-0258 CVE-2003-0259 CVE-2003-0260
|
|
| Description: |
The remote Cisco VPN 3000 concentrator is vulnerable to various flaws
which may allow an attacker to use this device
to break into a VPN, disable the remote device by sending
a malformed SSH initialization packet or disable the
remote device by sending a flood of malformed ICMP packets.
This vulnerability is documented with the CISCO
bugs ID CSCdea77143, CSCdz15393 and CSCdt84906
Solution : http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml
Risk factor : High
*** As solely relied on the banner of the remote host
*** this might be a false positive
|
|