Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.
| Software | From | Fixed in |
|---|---|---|
| cisco / vpn_client | 3.5.1c | 3.5.1c.x |
| cisco / vpn_client | 3.1 | 3.1.x |
| cisco / vpn_client | 3.5.1 | 3.5.1.x |
| cisco / vpn_client | 3.5.2 | 3.5.2.x |
| cisco / vpn_client | 3.0 | 3.0.x |
| cisco / vpn_client | 2.0 | 2.0.x |
| cisco / vpn_client | 3.0.5 | 3.0.5.x |