Cisco VPN Concentrator LAN-to-LAN IPSEC Tunnel Termination DoS (Bug ID CSCdx54675)

Medium Nessus Network Monitor Plugin ID 2238


The remote host is vulnerable to a Denial of Service (DoS) attack.


The remote VPN concentrator is subject to a LAN-to-LAN IPSEC tunnel vulnerability that allows remote attackers to cause a denial of service. Existing associations might be removed when a new connection is made and no check is done in order to determine if the connection comes from the proper network. This vulnerability is documented as Cisco bug ID CSCdx54675


Plugin Details

Severity: Medium

ID: 2238

Family: SNMP

Published: 2004/09/03

Modified: 2016/12/12

Nessus ID: 11296

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 5.3

Temporal Score: 4.6


Temporal Vector: CVSS3#E:U/RL:O/RC:C

Reference Information

CVE: CVE-2002-1102

BID: 5622