Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco IPsec VPN Implementation Group Name Enumeration Information Disclosure Vulnerability

Cisco-SA-20101203-CVE-2010-4354 · Medium · Published · Updated

Multiple Cisco VPN devices contain a vulnerability that could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability exists due to unsafe handling of error response codes.  An unauthenticated, remote attacker could exploit this vulnerability by sending malicious requests to the targeted device.  If successful, the attacker could determine the existence of VPN group names in use on the device. Cisco has confirmed the vulnerability in a security response and released software updates. Because the affected devices typically accept unsolicited connections from untrusted networks, an attacker could easily target a vulnerable system.  If an exploit is successful, the attacker could gain access to sensitive information about the device that could aid the attacker in further exploits. Administrators should note that Cisco PIX 500 Series devices and Cisco VPN 300 Series Concentrators have reached end of life.  As a result, no software updates will be issued for these products.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the available updates.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators may consider configuring devices to use certificate-based VPNs.

Administrators are advised to monitor critical systems.

CVEsCVE-2010-4354
Cisco Bug IDsNA
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco VPN 3000 Series Concentrator, Cisco PIX/ASA, Cisco Adaptive Security Appliance (ASA) Software 8.0.2.11, Cisco Adaptive Security Appliance (ASA) Software 8.0.4, Cisco Adaptive Security Appliance (ASA) Software 8.0.3, Cisco Adaptive Security Appliance (ASA) Software 8.0.2, Cisco Adaptive Security Appliance (ASA) Software 8.0.1.2, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.25, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.28, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.33, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.32, Cisco Adaptive Security Appliance (ASA) Software 8.0.5, Cisco Adaptive Security Appliance (ASA) Software 8.2.0.45, Cisco Adaptive Security Appliance (ASA) Software 8.2.1, Cisco Adaptive Security Appliance (ASA) Software 8.2.2, Cisco Adaptive Security Appliance (ASA) Software 8.2.2.10, Cisco Adaptive Security Appliance (ASA) Software 8.1.1, Cisco Adaptive Security Appliance (ASA) Software 8.1.2, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.15, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.16, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.19, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.23, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.24, Cisco Adaptive Security Appliance (ASA) Software 8.3.1.1, Cisco Adaptive Security Appliance (ASA) Software 8.3.1, Cisco Adaptive Security Appliance (ASA) Software

Related Products

Product CVE Evidence
Cisco VPN 3000 Series Concentrator CVE-2010-4354 Cisco OpenVuln
Cisco PIX/ASA CVE-2010-4354 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2010-4354 Cisco OpenVuln