CVE-2002-1108: Cisco VPN Client
Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.
Affected products
- Cisco VPN Client: version 2.0 only; version 3.0 only; version 3.0.5 only; version 3.1 only; version 3.5.1 only; version 3.5.1c only
Published 2002-10-04. Last modified 2026-06-16.