CVE-2002-1106

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*
cpe:2.3:a:cisco:vpn_client:3.0:*:windows:*:*:*:*:*
cpe:2.3:a:cisco:vpn_client:3.1:*:windows:*:*:*:*:*
cpe:2.3:a:cisco:vpn_client:3.5.1:*:windows:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://www.cisco.com/warp/public/707/vpnclient-multiple2-vuln-pub.shtml - Vendor Advisory () http://www.cisco.com/warp/public/707/vpnclient-multiple2-vuln-pub.shtml - Vendor Advisory
References () http://www.securityfocus.com/bid/5652 - Vendor Advisory () http://www.securityfocus.com/bid/5652 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/10045 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/10045 -

Information

Published : 2002-10-04 04:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1106

Mitre link : CVE-2002-1106

CVE.ORG link : CVE-2002-1106


JSON object : View

Products Affected

cisco

  • vpn_client