CVE-2005-2025
Last modified
CVE-2005-2025 is a vulnerability of currently unknown severity. Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.. EPSS estimates a 2.34% chance of exploitation in the next 30 days.
Description
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Vpn 3000 Concentrator | All versions |
| Cisco | Vpn 3015 Concentrator | All versions |
| Cisco | Vpn 3020 Concentrator | All versions |
| Cisco | Vpn 3030 Concentator | All versions |
| Cisco | Vpn 3060 Concentrator | All versions |
| Cisco | Vpn 3080 Concentrator | All versions |
| Cisco | Vpn 3000 Concentrator Series Software | 2.0 |
| Cisco | Vpn 3000 Concentrator Series Software | 2.5.2.a |
| Cisco | Vpn 3000 Concentrator Series Software | 2.5.2.b |
| Cisco | Vpn 3000 Concentrator Series Software | 2.5.2.c |
| Cisco | Vpn 3000 Concentrator Series Software | 2.5.2.d |
| Cisco | Vpn 3000 Concentrator Series Software | 2.5.2.f |
| Cisco | Vpn 3000 Concentrator Series Software | 3.0 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.0.3.a |
| Cisco | Vpn 3000 Concentrator Series Software | 3.0.3.b |
| Cisco | Vpn 3000 Concentrator Series Software | 3.0.4 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.1\(rel\) |
| Cisco | Vpn 3000 Concentrator Series Software | 3.1.1 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.1.2 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.1.4 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5\(rel\) |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5.1 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5.2 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5.3 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5.4 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.5.5 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.1 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.3 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.5 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7 |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7.a |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7.b |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7.c |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7.d |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7.f |
| Cisco | Vpn 3000 Concentrator Series Software | 3.6.7d |
| Cisco | Vpn 3000 Concentrator Series Software | 4.0 |
| Cisco | Vpn 3000 Concentrator Series Software | 4.0.1 |
| Cisco | Vpn 3000 Concentrator Series Software | 4.0.5.b |
| Cisco | Vpn 3000 Concentrator Series Software | 4.1 |
| Cisco | Vpn 3000 Concentrator Series Software | 4.1.5.b |
| Cisco | Vpn 3000 Concentrator Series Software | 4.1.7.a |
| Cisco | Vpn 3000 Concentrator Series Software | 4.1.7.b |
| Cisco | Vpn 3005 Concentrator Software | 4.0.1 |
References
- http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htmExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13992Patch, Vendor Advisory
- http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htmExploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13992Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2025?
How severe is CVE-2005-2025?
How do I fix CVE-2005-2025?
Are you affected by CVE-2005-2025?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
