5

CVE-2006-3906

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protocol, in which case other vendors and implementations would also be affected.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos
CiscoVpn 3030 Concentator Version4.7.1
CiscoVpn 3030 Concentator Version4.7.1.f
CiscoVpn 3030 Concentator Version4.7.2
CiscoVpn 3030 Concentator Version4.7.2.a
CiscoVpn 3030 Concentator Version4.7.2.f
CiscoPix Firewall Version6.2.2_.111
CiscoPix Firewall Software Version2.7
CiscoPix Firewall Software Version3.0
CiscoPix Firewall Software Version3.1
CiscoPix Firewall Software Version4.0
CiscoPix Firewall Software Version4.2
CiscoPix Firewall Software Version4.3
CiscoPix Firewall Software Version4.4
CiscoPix Firewall Software Version5.0
CiscoPix Firewall Software Version5.1
CiscoPix Firewall Software Version5.2
CiscoPix Firewall Software Version5.3
CiscoPix Firewall Software Version6.0
CiscoPix Firewall Software Version6.1
CiscoPix Firewall Software Version6.2
CiscoPix Firewall Software Version6.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.28% 0.884
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P