CVE-2002-0852
Cisco VPN Client 3.5.4 - Denial of Service via IKE SPI Payload or Large Payload Count
Title source: llmDescription
Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.
References (1)
Core 1
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/vpnclient-multiple-vuln-pub.shtml
Scores
EPSS
0.0130
EPSS Percentile
67.4%
Details
Status
published
Products (2)
cisco/vpn_client
3.5.1 (4 CPE variants)
cisco/vpn_client
3.5.2 (4 CPE variants)
Published
Sep 05, 2002
Tracked Since
Feb 18, 2026