← Vulnerability feed

Vulnerability record · CVE-2010-4354 · published 30 November 2010

CVE-2010-4354: Cisco asa 5500 information exposure vulnerability

Cisco · Asa 5500

The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.

5.0 CVSS 2.0 Medium EPSS 1.6% · top 25.4% CWE-200 · Information exposure
5.0CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-4354 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2010-4675Cisco adaptive security appliance software permissions and access controls vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET co…EPSS 2.8%9.0CVE-2010-4680Cisco adaptive security appliance software permissions and access controls vulnerabilityThe WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS sha…EPSS 2.8%9.0CVE-2007-0960Cisco asa 5500 vulnerabilityUnspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, all…EPSS 2.6%7.9CVE-2011-3298Cisco adaptive security appliance software improper authentication vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 0.86%7.9CVE-2011-0379Cisco adaptive security appliance software memory buffer overflow vulnerabilityBuffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devi…EPSS 2.2%7.8CVE-2011-3299Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.6%7.8CVE-2011-3300Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%7.8CVE-2011-3301Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2010-4354), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.