Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
BID:2573
Info
Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
| Bugtraq ID: | 2573 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2001 12:00AM |
| Updated: | Apr 12 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq in a Cisco Security Advisory dated April 12, 2001. |
| Vulnerable: |
Cisco VPN 3000 Concentrator 2.5.2 (D) Cisco VPN 3000 Concentrator 2.5.2 (C) Cisco VPN 3000 Concentrator 2.5.2 (B) Cisco VPN 3000 Concentrator 2.5.2 (A) |
| Not Vulnerable: |
Cisco VPN 3000 Concentrator 2.5.2 (F) |
Discussion
Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
The VPN 3000 Concentrator is a virtual private networking device distributed by Cisco Systems. The VPN 3000 Concentrator is designed to facilitate communications between two remote sites, providing the security cryptographic transit and the convience of seamless operation.
A problem with the VPN 3000 firmware could allow a denial of service to legitimate users of the device. Upon receipt of a custom crafted IP packet with specific options, the device becomes unstable. CPU utilization reaches 100 percent, and the system crashes, requiring a power cycling for the device to resume normal operation. No details on the nature of the IP packet, or specifically what options set within the packet are available.
Therefore, it is possible for a remote user to send a custom crafted IP packet with specific options to a VPN 3000 Concentrator, and deny service to legitimate users of network resources.
The VPN 3000 Concentrator is a virtual private networking device distributed by Cisco Systems. The VPN 3000 Concentrator is designed to facilitate communications between two remote sites, providing the security cryptographic transit and the convience of seamless operation.
A problem with the VPN 3000 firmware could allow a denial of service to legitimate users of the device. Upon receipt of a custom crafted IP packet with specific options, the device becomes unstable. CPU utilization reaches 100 percent, and the system crashes, requiring a power cycling for the device to resume normal operation. No details on the nature of the IP packet, or specifically what options set within the packet are available.
Therefore, it is possible for a remote user to send a custom crafted IP packet with specific options to a VPN 3000 Concentrator, and deny service to legitimate users of network resources.
Exploit / POC
Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
Solution:
Upgraded firmware is available:
Cisco VPN 3000 Concentrator 2.5.2 (B)
Cisco VPN 3000 Concentrator 2.5.2 (C)
Cisco VPN 3000 Concentrator 2.5.2 (D)
Cisco VPN 3000 Concentrator 2.5.2 (A)
Solution:
Upgraded firmware is available:
Cisco VPN 3000 Concentrator 2.5.2 (B)
-
Cisco VPN 3000 Concentrator 2.5.2(F)
http://www.cisco.com/public/sw-center/
Cisco VPN 3000 Concentrator 2.5.2 (C)
-
Cisco VPN 3000 Concentrator 2.5.2(F)
http://www.cisco.com/public/sw-center/
Cisco VPN 3000 Concentrator 2.5.2 (D)
-
Cisco VPN 3000 Concentrator 2.5.2(F)
http://www.cisco.com/public/sw-center/
Cisco VPN 3000 Concentrator 2.5.2 (A)
-
Cisco VPN 3000 Concentrator 2.5.2(F)
http://www.cisco.com/public/sw-center/
References
Cisco VPN 3000 Concertrator Malformed IP Packet Vulnerability
References:
References: