← Vulnerability feed

Vulnerability record · CVE-2003-0258 · published 27 May 2003

CVE-2003-0258: Cisco vpn 3015 concentrator vulnerability

Cisco · Vpn 3015 Concentrator

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

7.5 CVSS 2.0 High EPSS 2.2% · top 18.5%
7.5CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0258 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-0483Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user…EPSS 3.2%7.5CVE-2005-4499Cisco vpn 3001 concentrator vulnerabilityThe Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS)…EPSS 2.6%7.5CVE-2002-1092Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user …EPSS 1.4%7.5CVE-2002-1096Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HT…EPSS 1.3%7.5CVE-2002-1097Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintex…EPSS 1.1%7.5CVE-2002-1098Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY"…EPSS 1.3%7.1CVE-2001-0427Cisco vpn 3000 concentrator improper input validation vulnerabilityCisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) …EPSS 2.5%5.0CVE-2010-4354Cisco asa 5500 information exposure vulnerabilityThe remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series device…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2003-0258), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.