Back to search
CVE-2002-2139
Published: Nov 16, 2005
Modified: Sep 17, 2024
PUBLISHED
Description
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20021120 Cisco PIX Multiple Vulnerabilities
vendor-advisory
x_refsource_CISCO
N-017
third-party-advisory
government-resource
x_refsource_CIAC
6211
vdb-entry
x_refsource_BID
cisco-pix-isakmp-sa-mitm(10660)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now