Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml | patch vendor advisory |
http://www.osvdb.org/5643 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6298 | vdb entry |