{"api_version":"1","generated_at":"2026-07-23T09:51:03+00:00","cve":"CVE-2002-1092","urls":{"html":"https://cve.report/CVE-2002-1092","api":"https://cve.report/api/cve/CVE-2002-1092.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1092","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1092"},"summary":{"title":"CVE-2002-1092","description":"Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-10-04 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/5613","name":"http://www.securityfocus.com/bid/5613","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Internal Group Authentication External Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml","name":"http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco - Cisco Security Advisory: Cisco VPN 3000 Concentrator Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10017","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1092","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1092","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1092","vulnerable":"1","versionEndIncluding":"3.6\\(rel\\)","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"vpn_3000_concentrator_series_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:12:17.065Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml"},{"name":"cisco-vpn-bypass-authentication(10017)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10017"},{"name":"5613","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/5613"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-09-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2004-07-25T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml"},{"name":"cisco-vpn-bypass-authentication(10017)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10017"},{"name":"5613","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/5613"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1092","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml"},{"name":"cisco-vpn-bypass-authentication(10017)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10017"},{"name":"5613","refsource":"BID","url":"http://www.securityfocus.com/bid/5613"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1092","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2002-09-06T00:00:00.000Z","dateUpdated":"2024-08-08T03:12:17.065Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-10-04 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:*:*:*:*:*:*:*:*","versionEndIncluding":"3.6\\(rel\\)","matchCriteriaId":"8571BF7D-B151-44FF-98A6-DF9B172B12D0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1092","Ordinal":"1","Title":"CVE-2002-1092","CVE":"CVE-2002-1092","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1092","Ordinal":"1","NoteData":"Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.","Type":"Description","Title":"CVE-2002-1092"},{"CveYear":"2002","CveId":"1092","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1092","Ordinal":"3","NoteData":"2004-07-24","Type":"Other","Title":"Modified"}]}}}