Lucene search

K
cve[email protected]CVE-2006-2223
HistoryMay 05, 2006 - 7:02 p.m.

CVE-2006-2223

2006-05-0519:02:00
CWE-20
web.nvd.nist.gov
24
cve
2006
2223
ripd
quagga
security
vulnerability
remote attackers
sensitive information

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

87.8%

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

Affected configurations

NVD
Node
quaggaquaggaMatch0.98.5
OR
quaggaquaggaMatch0.99.3

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.017 Low

EPSS

Percentile

87.8%