Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-2224Improper Authentication in Routing Software Suite

Severity
5.0MEDIUMNVD
EPSS
20.2%
top 4.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 5
Latest updateMay 3

Description

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianquagga/quagga< 0.99.3-2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mj28-wp87-qqjj: RIPd in Quagga 02022-05-03
CVEList
CVE-2006-2224: RIPd in Quagga 02006-05-05
OSV
CVE-2006-2224: RIPd in Quagga 02006-05-05

💥Exploits & PoCs

1
Exploit-DB
Quagga Routing Software Suite 0.9x - RIPd RIPv1 RESPONSE Packet Route Injection2006-05-03

📋Vendor Advisories

2
Ubuntu
Quagga vulnerabilities2006-05-16
Red Hat
security flaw2006-05-03

💬Community

4
Bugzilla
CVE-2006-2224 security flaw2018-08-16
Bugzilla
CVE-2006-2224 zebra RIPd route injection2006-05-22
Bugzilla
CVE-2006-2224 Quagga RIPd route injection2006-05-08
Bugzilla
CVE-2006-2224 Quagga RIPd route injection2006-05-08
CVE-2006-2224 — Improper Authentication | cvebase