← Vulnerability feed

Vulnerability record · CVE-2005-2025 · published 20 June 2005

CVE-2005-2025: Cisco vpn 3000 concentrator vulnerability

Cisco · Vpn 3000 Concentrator

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

5.0 CVSS 2.0 Medium EPSS 2.3% · top 17.0%
5.0CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-0483Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user…EPSS 3.2%7.5CVE-2005-4499Cisco vpn 3001 concentrator vulnerabilityThe Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS)…EPSS 2.6%7.5CVE-2003-0258Cisco vpn 3015 concentrator vulnerabilityCisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentr…EPSS 2.2%7.5CVE-2002-1092Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user …EPSS 1.4%7.5CVE-2002-1096Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HT…EPSS 1.3%7.5CVE-2002-1097Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintex…EPSS 1.1%7.5CVE-2002-1098Cisco vpn 3000 concentrator series software vulnerabilityCisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY"…EPSS 1.3%7.1CVE-2001-0427Cisco vpn 3000 concentrator improper input validation vulnerabilityCisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2005-2025), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.