Cisco VPN 3000 Concentrator IPSEC...

- AV AC AU C I A
发布: 2002-09-03
修订: 2025-04-13

Cisco has reported a security vulnerability in VPN 3000 series concentrator devices. The vulnerability is related to handling of incoming LAN-to-LAN IPSEC tunnel connections. When a connection is initiated on behalf of a remote network for which the device already has a security association, the existing connection is terminated. According to Cisco, this behaviour may be exploitable as a denial of service attack. Furthermore, affected devices do not ensure that the data transmitted across a LAN-to-LAN IPSEC tunnel is sourced from the appropriate network. The implications of this potentially separate issue are not yet known.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息