CVE-2002-0848
Cisco VPN 5000 series <6.0.21.0002 & <5.2.23.0003 - Info Disclosure
Title source: llmDescription
Cisco VPN 5000 series concentrator hardware 6.0.21.0002 and earlier, and 5.2.23.0003 and earlier, when using RADIUS with a challenge type of Password Authentication Protocol (PAP) or Challenge, sends the user password in cleartext in a validation retry request, which could allow remote attackers to steal passwords via sniffing.
References (3)
Core 3
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/vpn5k-radius-pap-vuln-pub.shtml
Broken Link vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/9781.php
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5417
Scores
EPSS
0.0212
EPSS Percentile
80.0%
Details
Status
published
Products (1)
cisco/vpn_5000_concentrator_series_software
5.2.14 - 5.2.23.0003
Published
Aug 12, 2002
Tracked Since
Feb 18, 2026