Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Cisco VPN 3000 Concentrator
This vulnerability report for Cisco VPN 3000 Concentrator contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Cisco VPN 3000 Concentrator then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Cisco

Product Link N/A

Affected By 11 Secunia advisories
9 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 9% (1 of 11 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Cisco VPN 3000 Concentrator, with all vendor patches applied, is rated Less critical .




11 Secunia Advisories in 2003-2009
Secunia has issued a total of 11 Secunia advisories in 2003-2009 for Cisco VPN 3000 Concentrator. Currently, 9% (1 out of 11) are marked as unpatched with the most severe being rated Less critical

More information about the specific Secunia advisories affecting Cisco VPN 3000 Concentrator can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 4 in 2006. 11,064 views.
Release Date:
2006-08-24
Secunia Advisory ID:
SA21617
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Cisco VPN 3000 Concentrator, which can be exploited by malicious people to bypass certain security restrictions. [Read More]


Cisco WebVPN Cross-Site Scripting Vulnerability
Unpatched. Secunia Advisory 2 of 4 in 2006. 8,923 views.
Release Date:
2006-06-14
Secunia Advisory ID:
SA20644
Solution Status:
Unpatched
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
A vulnerability has been reported in Cisco WebVPN, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Cisco VPN 3000 Concentrator HTTP Packet Denial of Service
Vendor Patch. Secunia Advisory 3 of 4 in 2006. 13,133 views.
Release Date:
2006-01-27
Secunia Advisory ID:
SA18629
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Cisco VPN 3000 Concentrator, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Cisco Secure Access Control Server Downloadable IP Access Control List Vulnerability
Partial Fix. Secunia Advisory 4 of 4 in 2006. 13,982 views.
Release Date:
2006-01-03
Secunia Advisory ID:
SA18141
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Where:
From local network
Short Description:
ovt has reported a vulnerability in Cisco Secure ACS (Access Control Server), which potentially can be exploited by malicious people to bypass certain security restrictions. [Read More]


Cisco ISAKMP IKE Message Processing Denial of Service
Vendor Patch. Secunia Advisory 1 of 3 in 2005. 21,761 views.
Release Date:
2005-11-14
Secunia Advisory ID:
SA17553
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in various Cisco products, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Cisco IPsec VPN Implementation Group Name Enumeration Weakness
Vendor Patch. Secunia Advisory 2 of 3 in 2005. 12,240 views.
Release Date:
2005-06-21
Secunia Advisory ID:
SA15765
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
A weakness has been reported in certain Cisco products, which can be exploited by malicious people to gain knowledge of certain information. [Read More]


Cisco VPN Concentrator 3000 Series HTTPS Packet Denial of Service
Vendor Patch. Secunia Advisory 3 of 3 in 2005. 10,817 views.
Release Date:
2005-03-31
Secunia Advisory ID:
SA14784
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
A vulnerability has been reported in Cisco VPN Concentrator 3000 Series, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Cisco VPN 3000 Concentrator Multiple Kerberos Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 2 in 2004. 8,372 views.
Release Date:
2004-09-01
Secunia Advisory ID:
SA12410
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Cisco has acknowledged multiple vulnerabilities in the Kerberos implementation in Cisco VPN Concentrator 3000, where the most critical potentially can be exploited by malicious people to compromise a vulnerable device. [Read More]


Cisco IPsec VPN Implementation Group/User Password Disclosure
Vendor Workaround. Secunia Advisory 2 of 2 in 2004. 17,108 views.
Release Date:
2004-04-16
Secunia Advisory ID:
SA11387
Solution Status:
Vendor Workaround
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
Two security issues have been reported in the Cisco's IPsec VPN implementation, which can be exploited by malicious, local users to gain knowledge of sensitive information. [Read More]


Cisco VPN 3000 Concentrator Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2003. 7,385 views.
Release Date:
2003-05-08
Secunia Advisory ID:
SA8746
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
DoS
Where:
From remote
Short Description:
Cisco has released a security bulletin describing three vulnerabilities in VPN 3000 Concentrator. These allow malicious people to access internal hosts or cause a Denial of Service. [Read More]


Cisco VPN 3000 Concentrator Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2002. 4,706 views.
Release Date:
2002-09-03
Secunia Advisory ID:
SA7064
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Exposure of sensitive information
Exposure of system information
Where:
From remote
Short Description:
The Cisco VPN 3000 Concentrator series and Cisco VPN 3002 Hardware Client are vulnerable to many different attacks, ranging from DoS attack, exposing too much system information, revealing passwords to low privileged admin accounts, access to admin pages to non authenticated users, insufficient filtering of certain traffic. [Read More]