xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Cisco VPN 3000 Series Concentrator客户端验证存在拒绝服务攻击问题


发布时间:2002-09-10
更新时间:2002-09-10
严重程度:
威胁程度:远程拒绝服务
错误类型:意外情况处置错误
利用方式:服务器模式

BUGTRAQ ID:5620

受影响系统
Cisco VPN 3000 Concentrator 2.0
Cisco VPN 3000 Concentrator 2.5.2 (F)
Cisco VPN 3000 Concentrator 2.5.2 (D)
Cisco VPN 3000 Concentrator 2.5.2 (C)
Cisco VPN 3000 Concentrator 2.5.2 (B)
Cisco VPN 3000 Concentrator 2.5.2 (A)
Cisco VPN 3000 Concentrator 3.0 (Rel)
Cisco VPN 3000 Concentrator 3.0
Cisco VPN 3000 Concentrator 3.0.3 (B)
Cisco VPN 3000 Concentrator 3.0.3 (A)
Cisco VPN 3000 Concentrator 3.0.4
Cisco VPN 3000 Concentrator 3.1 (Rel)
Cisco VPN 3000 Concentrator 3.1
Cisco VPN 3000 Concentrator 3.1.1
Cisco VPN 3000 Concentrator 3.1.2
Cisco VPN 3000 Concentrator 3.1.4
Cisco VPN 3000 Concentrator 3.5 (Rel)
Cisco VPN 3000 Concentrator 3.5.1
Cisco VPN 3000 Concentrator 3.5.2
Cisco VPN 3000 Concentrator 3.5.3
Cisco VPN 3000 Concentrator 3.5.4
Cisco VPN 3000 Concentrator 3.6 (Rel)
Cisco VPN 3002 Hardware Client
详细描述
Cisco VPN 3000 series concentrators是一系列通过VPN进行安全通信的产品。

Cisco VPN 3000 series concentrators在处理认证的时候存在问题,远程VPN客户端只要提交超长的用户名可导致设备重新装载,产生拒绝服务。

测试代码


解决方案
联系供应商固件升级:

Cisco VPN 3002 Hardware Client :
Cisco VPN 3000 Concentrator 2.0:
Cisco VPN 3000 Concentrator 2.5.2 (F):
Cisco VPN 3000 Concentrator 2.5.2 (D):
Cisco VPN 3000 Concentrator 2.5.2 (C):
Cisco VPN 3000 Concentrator 2.5.2 (B):
Cisco VPN 3000 Concentrator 2.5.2 (A):
Cisco VPN 3000 Concentrator 3.0 (Rel):
Cisco VPN 3000 Concentrator 3.0:
Cisco VPN 3000 Concentrator 3.0.3 (B):
Cisco VPN 3000 Concentrator 3.0.3 (A):
Cisco VPN 3000 Concentrator 3.0.4:
Cisco VPN 3000 Concentrator 3.1 (Rel):
Cisco VPN 3000 Concentrator 3.1:
Cisco VPN 3000 Concentrator 3.1.1:
Cisco VPN 3000 Concentrator 3.1.2:
Cisco VPN 3000 Concentrator 3.1.4:
Cisco VPN 3000 Concentrator 3.5 (Rel):

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.1:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.2:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.3:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

相关信息
Cisco Security Advisory.
参考:http://online.securityfocus.com/advisories/4446