CVE-2002-0852

Cisco VPN Client 3.5.4 - Denial of Service via IKE SPI Payload or Large Payload Count

Title source: llm
STIX 2.1

Description

Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/vpnclient-multiple-vuln-pub.shtml

Scores

EPSS 0.0130
EPSS Percentile 67.4%

Details

Status published
Products (2)
cisco/vpn_client 3.5.1 (4 CPE variants)
cisco/vpn_client 3.5.2 (4 CPE variants)
Published Sep 05, 2002
Tracked Since Feb 18, 2026