CVE-2006-3894

CWE-3994 documents4 sources
Severity
5.0MEDIUM
EPSS
12.3%
top 6.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 1

Description

The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-m7g4-rpgq-jc74: The RSA Crypto-C before 62022-05-01
CVEList
CVE-2006-3894: The RSA Crypto-C before 62007-05-22

📋Vendor Advisories

1
Cisco
Vulnerability In Crypto Library2007-05-22
CVE-2006-3894 (MEDIUM CVSS 5) | The RSA Crypto-C before 6.3.1 and C | cvebase.io