CVE-2002-1492 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 1.7% (pctl 77)
Patch early
A public exploit exists.
Description
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.72% — more likely to be exploited than 77% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-04-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cisco | vpn 5000 client |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco VPN 5000 Client - Buffer Overrun (1) | 2002-09-18 |
| exploit-db | Cisco VPN 5000 Client - Buffer Overrun (2) | 2002-09-18 |
References
- http://www.cisco.com/warp/public/707/vpn5k-client-multiple-vuln-pub.shtml
- http://www.iss.net/security_center/static/10131.php
- http://www.securityfocus.com/bid/5734
- http://www.cisco.com/warp/public/707/vpn5k-client-multiple-vuln-pub.shtml
- http://www.iss.net/security_center/static/10131.php
- http://www.securityfocus.com/bid/5734
→ the Explorer · watch your stack · NVD