← Back

Vpn 3000 Concentrator

vpn_3000_concentrator

Vendor: Cisco • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
9Asa 5500
Pix 500Vpn 3000 Concentrator+6 more
Apr 29, 2026
Nov 30, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive...Show more
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.Show less
1Cisco
8Vpn 3000 Concentrator
Vpn 3000 Concentrator Series SoftwareVpn 3005 Concentrator Software+5 more
Apr 16, 2026
Jun 20, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is...Show more
Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.Show less
1Cisco
6Vpn 3000 Concentrator
Vpn 3005 ConcentratorVpn 3015 Concentrator+3 more
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disco...Show more
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.Show less