VYPR
Unrated severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026

CVE-2002-1106

CVE-2002-1106

Description

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.

Affected products

4
  • cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*+ 3 more
    • cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*
    • cpe:2.3:a:cisco:vpn_client:3.0:*:windows:*:*:*:*:*
    • cpe:2.3:a:cisco:vpn_client:3.1:*:windows:*:*:*:*:*
    • cpe:2.3:a:cisco:vpn_client:3.5.1:*:windows:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.