CVE Database
/

CVE-2002-2139

Back to search

CVE-2002-2139

Published: Nov 16, 2005

Modified: Sep 17, 2024

PUBLISHED

Description

Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

20021120 Cisco PIX Multiple Vulnerabilities
vendor-advisory
x_refsource_CISCO
N-017
third-party-advisory
government-resource
x_refsource_CIAC
6211
vdb-entry
x_refsource_BID
cisco-pix-isakmp-sa-mitm(10660)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now