Lucene search

K
nvd[email protected]NVD:CVE-2006-5179
HistoryOct 10, 2006 - 4:06 a.m.

CVE-2006-5179

2006-10-1004:06:00
web.nvd.nist.gov
1

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

Low

EPSS

0.094

Percentile

94.8%

Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) “public exponent” or (2) “public modulus” values in X.509 certificates that require extra time to process when using RSA signature verification, a related issue to CVE-2006-2940.

Affected configurations

NVD
Node
intotoigateway_ssl-vpn
OR
intotoigateway_vpn

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

Low

EPSS

0.094

Percentile

94.8%