xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Cisco VPN 3000 Series Concentrator WEB验证存在拒绝服务攻击


发布时间:2002-09-10
更新时间:2002-09-10
严重程度:
威胁程度:远程拒绝服务
错误类型:意外情况处置错误
利用方式:服务器模式

BUGTRAQ ID:5617

受影响系统
Cisco VPN 3000 Concentrator 2.0
Cisco VPN 3000 Concentrator 2.5.2 (F)
Cisco VPN 3000 Concentrator 2.5.2 (D)
Cisco VPN 3000 Concentrator 2.5.2 (C)
Cisco VPN 3000 Concentrator 2.5.2 (B)
Cisco VPN 3000 Concentrator 2.5.2 (A)
Cisco VPN 3000 Concentrator 3.0 (Rel)
Cisco VPN 3000 Concentrator 3.0
Cisco VPN 3000 Concentrator 3.0.3 (B)
Cisco VPN 3000 Concentrator 3.0.3 (A)
Cisco VPN 3000 Concentrator 3.0.4
Cisco VPN 3000 Concentrator 3.1 (Rel)
Cisco VPN 3000 Concentrator 3.1
Cisco VPN 3000 Concentrator 3.1.1
Cisco VPN 3000 Concentrator 3.1.2
Cisco VPN 3000 Concentrator 3.1.4
Cisco VPN 3000 Concentrator 3.5 (Rel)
Cisco VPN 3000 Concentrator 3.5.1
Cisco VPN 3000 Concentrator 3.5.2
Cisco VPN 3002 Hardware Client
详细描述
Cisco VPN 3000 series concentrators是一系列通过VPN进行安全通信的产品。

Cisco VPN 3000 series concentrators当处理通过WEB接口登录页登录存在问题,如果用户通过修改表单内容使用POST方式发送超长的用户名/密码到WEB接口登录页,可导致设备重载。

测试代码


解决方案
联系供应商固件升级:

Cisco VPN 3002 Hardware Client :
Cisco VPN 3000 Concentrator 2.0:
Cisco VPN 3000 Concentrator 2.5.2 (F):
Cisco VPN 3000 Concentrator 2.5.2 (D):
Cisco VPN 3000 Concentrator 2.5.2 (C):
Cisco VPN 3000 Concentrator 2.5.2 (B):
Cisco VPN 3000 Concentrator 2.5.2 (A):
Cisco VPN 3000 Concentrator 3.0 (Rel):
Cisco VPN 3000 Concentrator 3.0:
Cisco VPN 3000 Concentrator 3.0.3 (B):
Cisco VPN 3000 Concentrator 3.0.3 (A):
Cisco VPN 3000 Concentrator 3.0.4:
Cisco VPN 3000 Concentrator 3.1 (Rel):
Cisco VPN 3000 Concentrator 3.1:
Cisco VPN 3000 Concentrator 3.1.1:
Cisco VPN 3000 Concentrator 3.1.2:
Cisco VPN 3000 Concentrator 3.1.4:
Cisco VPN 3000 Concentrator 3.5 (Rel):

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.1:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.2:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

Cisco VPN 3000 Concentrator 3.5.3:

Cisco Upgrade VPN 3000 Concentrator 3.5.4
http://www.cisco.com/tac

相关信息
Cisco Security Advisory.
参考:http://online.securityfocus.com/advisories/4446