CVE-2002-0848 describes a vulnerability in Cisco VPN 5000 series concentrators (versions 6.0.21.0002 and earlier, and 5.2.23.0003 and earlier) when configured to use RADIUS with PAP or Challenge authentication. This flaw causes user passwords to be transmitted in cleartext during validation retry requests, making them susceptible to interception. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and the potential for unauthorized information disclosure (password theft) via network sniffing. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the CVE has garnered significant community discussion with 10 mentions, suggesting awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2.14, <= 5.2.23.0003CPE matchmatch criteria | cpe:2.3:o:cisco:vpn_5000_concentrator_series_software:*:*:*:*:*:*:*:* | ||
>= 6.0.15, <= 6.0.21.0002CPE matchmatch criteria | cpe:2.3:o:cisco:vpn_5000_concentrator_series_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.