CVE-2006-3906
published 2006-07-27CVE-2006-3906: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.75%
93.2th percentile
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protocol, in which case other vendors and implementations would also be affected.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | pix_firewall | — | — |
| cisco | pix_firewall | — | — |
| cisco | pix_firewall | — | — |
| cisco | pix_firewall | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Internet Key Exchange Protocol Version 1 Denial of Service Vulnerability
vendor_cisco·2006-07-27·CVSS 5.0
CVE-2006-3906 [MEDIUM] CWE-399 Internet Key Exchange Protocol Version 1 Denial of Service Vulnerability
Internet Key Exchange Protocol Version 1 Denial of Service Vulnerability
Multiple products contain a vulnerability in the implementation of the Internet Key Exchange (IKE) version 1 protocol. IKE is typically used for key exchange in IPSec, and IPSec is commonly used to encrypt data for VPN connections.
The vulnerability affects IKE Phase 1 negotiations in both Main Mode and Aggressive Mode. It affects normal UDP-based IKE as well as Cisco-proprietary TCP-encapsulated IKE. The vulnerability exists due to improper handling of overly large amounts of IKE requests sent to a system. An affected device can only queue so many initial requests for IKE sessions before they fill the request queue. An attacker could exploit this vulnerability to exhaust the IKE resources by initiating numerous
IKE
GHSA
GHSA-v43w-r88q-4mh9: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cau
ghsa_unreviewed·2022-05-01
CVE-2006-3906 [MEDIUM] GHSA-v43w-r88q-4mh9: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cau
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protocol, in which case other vendors and implementations would also be affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2006-07/0531.htmlhttp://securityreason.com/securityalert/1293http://securitytracker.com/id?1016582http://www.cisco.com/en/US/tech/tk583/tk372/tsd_technology_security_response09186a00806f33d4.htmlhttp://www.nta-monitor.com/posts/2006/07/cisco-concentrator-dos.htmlhttp://www.osvdb.org/29068http://www.securityfocus.com/archive/1/441203/100/0/threadedhttp://www.securityfocus.com/bid/19176https://exchange.xforce.ibmcloud.com/vulnerabilities/27972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5299http://archives.neohapsis.com/archives/bugtraq/2006-07/0531.htmlhttp://securityreason.com/securityalert/1293http://securitytracker.com/id?1016582http://www.cisco.com/en/US/tech/tk583/tk372/tsd_technology_security_response09186a00806f33d4.htmlhttp://www.nta-monitor.com/posts/2006/07/cisco-concentrator-dos.htmlhttp://www.osvdb.org/29068http://www.securityfocus.com/archive/1/441203/100/0/threadedhttp://www.securityfocus.com/bid/19176https://exchange.xforce.ibmcloud.com/vulnerabilities/27972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5299
2006-07-27
Published