CVE-2002-1108: Cisco VPN Client

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.

Affected products

  • Cisco VPN Client: version 2.0 only; version 3.0 only; version 3.0.5 only; version 3.1 only; version 3.5.1 only; version 3.5.1c only

Published 2002-10-04. Last modified 2026-06-16.