Vulnerability Details CVE-2002-1097
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2002-1097
-
cpe:2.3:a:cisco:vpn_3002_hardware_client:-
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.0
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.5.2.a
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.5.2.b
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.5.2.c
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.5.2.d
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:2.5.2.f
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.0
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.0(rel)
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.0.3.a
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.0.3.b
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.0.4
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.1
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.1(rel)
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.1.1
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.1.2
-
cpe:2.3:o:cisco:vpn_3000_concentrator_series_software:3.5(rel)