MEDIUM · 5.0

CVE-2006-3906

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a...

Vulnerability Description

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protocol, in which case other vendors and implementations would also be affected.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoIosAll versions
CiscoVpn 3001 ConcentratorAll versions
CiscoVpn 3015 ConcentratorAll versions
CiscoVpn 3020 ConcentratorAll versions
CiscoVpn 3030 ConcentatorAll versions
CiscoVpn 3060 ConcentratorAll versions
CiscoVpn 3080 ConcentratorAll versions
CiscoAdaptive Security Appliance Software7.0
CiscoVpn 3000 Concentrator Series Software2.0
CiscoVpn 3005 Concentrator Software4.0.1
CiscoPix Asa IdsAll versions
CiscoPix Firewall6.2.2_.111
CiscoPix Firewall 501All versions
CiscoPix Firewall 506All versions
CiscoPix Firewall 515All versions
CiscoPix Firewall 515EAll versions
CiscoPix Firewall 520All versions
CiscoPix Firewall 525All versions
CiscoPix Firewall 535All versions
CiscoSecure Pix FirewallAll versions

References

FAQ

What is CVE-2006-3906?

CVE-2006-3906 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a...

How severe is CVE-2006-3906?

CVE-2006-3906 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-3906?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Vpn 3001 Concentrator, Cisco Vpn 3015 Concentrator, Cisco Vpn 3020 Concentrator, Cisco Vpn 3030 Concentator.