Description Preview
Cisco Virtual Private Network (VPN) Client versions 3.5.4 and earlier contain a denial-of-service vulnerability that allows remote attackers to cause excessive CPU consumption by sending a packet with a zero-length payload. This issue can disrupt VPN client availability and does not require user interaction beyond sending the crafted packet. The vulnerability is documented in multiple sources, including Cisco advisories and third-party reports, and affects the affected Cisco VPN Client versions.
Overview
This CVE describes a denial-of-service vulnerability in Cisco VPN Client versions 3.5.4 and earlier where processing a zero-length payload packet can cause the client to consume CPU resources, potentially impacting availability. The vulnerability is exploitable remotely and has been documented by Cisco and other vulnerability trackers, with affected versions identified as Cisco VPN Client 3.5.4 and earlier.
Remediation
- Upgrade the Cisco VPN Client to a non-affected version per Cisco’s advisory or migrate to a supported Cisco VPN solution, and ensure ongoing security updates.
- If upgrading is not immediately feasible, implement network-level mitigations such as blocking or rate-limiting packets with zero-length payloads at the perimeter (firewall/IPS) and restricting VPN client access to reduce exposure.
- Enable robust monitoring for unusual VPN client CPU usage and potential DoS attempts; conduct testing after applying patches.
- If the product is end-of-life or no fixed version is available, consider replacing with a supported VPN solution to ensure ongoing security patching.
References
- Cisco VPN Client Multiple Vulnerabilities (Cisco) — http://www.cisco.com/warp/public/707/vpnclient-multiple-vuln-pub.shtml
- VU#287771 (CERT/CSRIC) — http://www.kb.cert.org/vuls/id/287771
- BID 5440 (SecurityFocus) — http://www.securityfocus.com/bid/5440
- cisco-vpn-zerolength-dos(9821) (ISS XF) — http://www.iss.net/security_center/static/9821.php
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- ConstructionConstruction: Low
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Health Care & Social AssistanceHealth Care & Social Assistance: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- ManufacturingManufacturing: Low
- MiningMining: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Public AdministrationPublic Administration: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Retail TradeRetail Trade: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low

