Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco VPN 3000 Series Concentrator Posted User Credential Denial Of Service Vulnerability

Cisco VPN 3000 series concentrators are prone to a denial of service condition when handling overly long username/password strings via login pages for the web interface of the device. To exploit this condition, the attacker must submit overly long values for the username/password strings using the POST method. The attacker might, for example, submit a modified version of the form for the login page to trigger this condition.

Successful exploitation will cause the device to reload.







 

Privacy Statement
Copyright 2008, SecurityFocus