VulnerabilityModified
CVE-2006-2224
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
MEDIUM 5.0EPSS 10.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 10.36% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- quagga/quagga routing software suite
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
- http://bugzilla.quagga.net/show_bug.cgi?id=262Patch
- http://secunia.com/advisories/19910Patch, Vendor Advisory
- http://secunia.com/advisories/20137Vendor Advisory
- http://secunia.com/advisories/20138Vendor Advisory
- http://secunia.com/advisories/20221Vendor Advisory
- http://secunia.com/advisories/20420Vendor Advisory
- http://secunia.com/advisories/20421Vendor Advisory
- http://secunia.com/advisories/20782Vendor Advisory
- http://secunia.com/advisories/21159Vendor Advisory
- http://securitytracker.com/id?1016204
- http://www.debian.org/security/2006/dsa-1059
- http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
- http://www.novell.com/linux/security/advisories/2006_17_sr.html
- http://www.osvdb.org/25225
- http://www.redhat.com/support/errata/RHSA-2006-0525.html
- http://www.redhat.com/support/errata/RHSA-2006-0533.html
- http://www.securityfocus.com/archive/1/432823/100/0/threaded
- http://www.securityfocus.com/archive/1/432856/100/0/threaded
- http://www.securityfocus.com/bid/17808Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26251
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10775
- https://usn.ubuntu.com/284-1/
- ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
- http://bugzilla.quagga.net/show_bug.cgi?id=262Patch
- http://secunia.com/advisories/19910Patch, Vendor Advisory
- http://secunia.com/advisories/20137Vendor Advisory
- http://secunia.com/advisories/20138Vendor Advisory
- http://secunia.com/advisories/20221Vendor Advisory
- http://secunia.com/advisories/20420Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.