CVE-2006-4613
Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulnerable versions of ClamAV before 0.88.4.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulnerable versions of ClamAV before 0.88.4. NOTE: it is possible that vector 2 is related to CVE-2006-4018.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- securecomputing/snapgear sg560 · securecomputing/snapgear sg565 · securecomputing/snapgear sg580 · securecomputing/snapgear sg710
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21707Patch, Vendor Advisory
- http://www.cyberguard.info/snapgear/releases.htmlPatch, URL Repurposed
- http://www.securityfocus.com/bid/19805Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28702
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28705
- http://secunia.com/advisories/21707Patch, Vendor Advisory
- http://www.cyberguard.info/snapgear/releases.htmlPatch, URL Repurposed
- http://www.securityfocus.com/bid/19805Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28702
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28705
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.