← Vulnerability feed

Vulnerability record · CVE-2002-1097 · published 4 October 2002

CVE-2002-1097: Cisco vpn 3000 concentrator series software vulnerability

Cisco · Vpn 3000 Concentrator Series Software

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

7.5 CVSS 2.0 High EPSS 1.1% · top 34.9%
7.5CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-0483Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user…EPSS 3.2%7.5CVE-2005-4499Cisco vpn 3001 concentrator vulnerabilityThe Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS)…EPSS 2.6%7.5CVE-2003-0258Cisco vpn 3015 concentrator vulnerabilityCisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentr…EPSS 2.2%7.5CVE-2002-1092Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user …EPSS 1.4%7.5CVE-2002-1096Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HT…EPSS 1.3%7.5CVE-2002-1098Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY"…EPSS 1.3%5.0CVE-2006-4313Cisco vpn 3000 concentrator series software vulnerabilityMultiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers …EPSS 12%5.0CVE-2006-3906Cisco ios vulnerabilityInternet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to ca…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2002-1097), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.