Remote Authentication Bypass in Cisco VPN 3000 Concentrator
CVE-2002-1092
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 4 October 2002
What is CVE-2002-1092?
The Cisco VPN 3000 Concentrator, specifically versions 3.6(Rel) and earlier, allows remote VPN clients to bypass intended user authentication when configured to utilize internal authentication with group accounts alone. This misconfiguration can lead to unauthorized access via PPTP or IPSEC protocols, posing significant security risks to networks relying on these VPN connections. Administrators must ensure that appropriate user accounts are established to mitigate this vulnerability.