← Vulnerability feed

Vulnerability record · CVE-2001-1105 · published 12 September 2001

CVE-2001-1105: Cisco icdn vulnerability

Cisco · Icdn

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

7.5 CVSS 2.0 High EPSS 2.7% · top 14.7%
7.5CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1105 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34381Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party com…EPSS 0.98%7.5CVE-2024-29171Dell bsafe ssl-j improper certificate validation vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …EPSS 0.33%7.5CVE-2024-29172Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit …EPSS 0.45%7.5CVE-2022-24409Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected s…EPSS 0.96%7.5CVE-2015-0534Dell bsafe improper certificate validation vulnerabilityEMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA…EPSS 1.4%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%6.5CVE-2019-3738Dell bsafe cert-j improper verification of cryptographic signature vulnerabilityRSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could p…EPSS 1.7%6.5CVE-2019-3739Dell bsafe cert-j observable discrepancy vulnerabilityRSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generat…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2001-1105), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.