← Back

CVE-2005-2025

nvd nist
Published: Jun 20, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

Affected (44)

8 products
Vpn 3000 Concentrator
Vpn 3005 Concentrator Software
Vpn 3015 Concentrator
Vpn 3020 Concentrator
Vpn 3030 Concentator
Vpn 3060 Concentrator
Vpn 3080 Concentrator
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Cisco
Version 2.0
Version 2.5.2.a
Version 2.5.2.b
Version 2.5.2.c
Version 2.5.2.d
Version 2.5.2.f
Version 3.0.3.a
Version 3.0.3.b
Version 3.0.4
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1.4
Version 3.1(rel)
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.5.4
Version 3.5.5
Version 3.5(rel)
Version 3.6.1
Version 3.6.3
Version 3.6.5
Version 3.6.7.a
Version 3.6.7.b
Version 3.6.7.c
Version 3.6.7.d
Version 3.6.7.f
Version 3.6.7
Version 3.6.7d
Version 4.0.1
Version 4.0.5.b
Version 4.0
Version 4.1.5.b
Version 4.1.7.a
Version 4.1.7.b
Version 4.1
Version 4.0.1
All versions
All versions
All versions
All versions
All versions

References (6)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.