peter bassill · operator
$ cve CVE-2006-2223 JSON

CVE-2006-2223 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 11.3% (pctl 96)

Patch early

A public exploit exists.

Description

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS11.28% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2006-05-05
Last modified2026-06-16

Affected (1)

VendorProduct
quaggaquagga

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD