CVE Database
/

CVE-2006-3906

Back to search

CVE-2006-3906

Published: Jul 27, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protocol, in which case other vendors and implementations would also be affected.

VendorProductVersions

n/a

n/a

affected
n/a

References

19176
vdb-entry
x_refsource_BID
29068
vdb-entry
x_refsource_OSVDB
oval:org.mitre.oval:def:5299
vdb-entry
signature
x_refsource_OVAL
1016582
vdb-entry
x_refsource_SECTRACK
1293
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now