CVE-2006-1646
Summary
| CVE | CVE-2006-1646 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-06 10:04:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to cause a denial of service (daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS: 0.011080000 probability, percentile 0.781410000 (date 2026-04-19)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Internet Key Exchange | Internet Key Exchange | 1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| source-changes: CVS commit: [netbsd-2-1] src/crypto/dist/kame/racoon | af854a3a-2127-422b-91ae-364da2661108 | mail-index.netbsd.org | |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-003.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| NetBSD racoon IKE Message Processing Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.niscc.gov.uk | |
| www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp | af854a3a-2127-422b-91ae-364da2661108 | www.ee.oulu.fi | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.