← Vulnerability feed

Vulnerability record · CVE-2001-0427 · published 18 June 2001

CVE-2001-0427: Cisco vpn 3000 concentrator improper input validation vulnerability

Cisco · Vpn 3000 Concentrator

Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.

7.1 CVSS 2.0 High EPSS 2.5% · top 15.8% CWE-20 · Improper input validation
7.1CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.

AV:N/AC:M/Au:N/C:N/I:N/A:C

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-0483Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user…EPSS 3.2%7.5CVE-2005-4499Cisco vpn 3001 concentrator vulnerabilityThe Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS)…EPSS 2.6%7.5CVE-2003-0258Cisco vpn 3015 concentrator vulnerabilityCisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentr…EPSS 2.2%5.0CVE-2010-4354Cisco asa 5500 information exposure vulnerabilityThe remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series device…EPSS 1.6%5.0CVE-2006-3906Cisco ios vulnerabilityInternet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to ca…EPSS 6.9%5.0CVE-2005-2025Cisco vpn 3000 concentrator vulnerabilityCisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the gr…EPSS 2.3%5.0CVE-2005-0943Cisco vpn 3015 concentrator vulnerabilityCisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop u…EPSS 1.6%5.0CVE-2003-0259Cisco vpn 3015 concentrator vulnerabilityCisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (relo…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2001-0427), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.