peter bassill · operator
$ cve CVE-2006-2224 JSON

CVE-2006-2224 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 10.4% (pctl 96)

Patch early

A public exploit exists.

Description

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS10.36% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2006-05-05
Last modified2026-06-16

Affected (1)

VendorProduct
quaggaquagga routing software suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD