{"api_version":"1","generated_at":"2026-07-23T08:36:04+00:00","cve":"CVE-2006-2223","urls":{"html":"https://cve.report/CVE-2006-2223","api":"https://cve.report/api/cve/CVE-2006-2223.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2223","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2223"},"summary":{"title":"CVE-2006-2223","description":"RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-05-05 19:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.redhat.com/support/errata/RHSA-2006-0533.html","name":"http://www.redhat.com/support/errata/RHSA-2006-0533.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0525.html","name":"http://www.redhat.com/support/errata/RHSA-2006-0525.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20138","name":"http://secunia.com/advisories/20138","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Gentoo update for quagga - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17808","name":"http://www.securityfocus.com/bid/17808","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Quagga Information Disclosure and Route Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.debian.org/security/2006/dsa-1059","name":"http://www.debian.org/security/2006/dsa-1059","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1059-1 quagga","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20137","name":"http://secunia.com/advisories/20137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Ubuntu update for Quagga - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20221","name":"http://secunia.com/advisories/20221","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Debian update for quagga - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20420","name":"http://secunia.com/advisories/20420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for zebra - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Quagga Routing Suite: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19910","name":"http://secunia.com/advisories/19910","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Quagga RIPd RIPv1 Request Handling Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_17_sr.html","name":"http://www.novell.com/linux/security/advisories/2006_17_sr.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/432823/100/0/threaded","name":"http://www.securityfocus.com/archive/1/432823/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26243","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26243","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016204","name":"http://securitytracker.com/id?1016204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Quagga Bugs Let Remote Users Obtain or Modify Routing Information and Local Users Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20782","name":"http://secunia.com/advisories/20782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugzilla.quagga.net/show_bug.cgi?id=261","name":"http://bugzilla.quagga.net/show_bug.cgi?id=261","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"261 – arh200604-1: RIPd unauthenticated route table broadcast","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/432822/100/0/threaded","name":"http://www.securityfocus.com/archive/1/432822/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc","name":"ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/284-1/","name":"https://usn.ubuntu.com/284-1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-284-1: Quagga vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20421","name":"http://secunia.com/advisories/20421","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for quagga - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/25224","name":"http://www.osvdb.org/25224","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/21159","name":"http://secunia.com/advisories/21159","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE Updates for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2223","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2223","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2223","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"quagga","cpe5":"quagga","cpe6":"0.98.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2223","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"quagga","cpe5":"quagga","cpe6":"0.99.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"2223","cve":"CVE-2006-2223","epss":"0.127980000","percentile":"0.940380000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:43:28.938Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SUSE-SR:2006:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2006_17_sr.html"},{"name":"USN-284-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/284-1/"},{"name":"quagga-ripv1-information-disclosure(26243)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26243"},{"name":"20782","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20782"},{"name":"20138","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20138"},{"name":"20060503 Re: Quagga RIPD unauthenticated route injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/432823/100/0/threaded"},{"name":"20421","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20421"},{"name":"20060602-01-U","tags":["vendor-advisory","x_refsource_SGI","x_transferred"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"},{"name":"25224","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/25224"},{"name":"RHSA-2006:0525","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2006-0525.html"},{"name":"20137","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20137"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugzilla.quagga.net/show_bug.cgi?id=261"},{"name":"1016204","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1016204"},{"name":"19910","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19910"},{"name":"oval:org.mitre.oval:def:9985","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985"},{"name":"17808","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17808"},{"name":"RHSA-2006:0533","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2006-0533.html"},{"name":"GLSA-200605-15","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml"},{"name":"21159","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/21159"},{"name":"20060503 Quagga RIPD unauthenticated route table broadcast","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/432822/100/0/threaded"},{"name":"DSA-1059","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2006/dsa-1059"},{"name":"20221","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20221"},{"name":"20420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20420"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-05-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"SUSE-SR:2006:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2006_17_sr.html"},{"name":"USN-284-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/284-1/"},{"name":"quagga-ripv1-information-disclosure(26243)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26243"},{"name":"20782","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20782"},{"name":"20138","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20138"},{"name":"20060503 Re: Quagga RIPD unauthenticated route injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/432823/100/0/threaded"},{"name":"20421","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20421"},{"name":"20060602-01-U","tags":["vendor-advisory","x_refsource_SGI"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"},{"name":"25224","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/25224"},{"name":"RHSA-2006:0525","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2006-0525.html"},{"name":"20137","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20137"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugzilla.quagga.net/show_bug.cgi?id=261"},{"name":"1016204","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1016204"},{"name":"19910","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19910"},{"name":"oval:org.mitre.oval:def:9985","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985"},{"name":"17808","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17808"},{"name":"RHSA-2006:0533","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2006-0533.html"},{"name":"GLSA-200605-15","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml"},{"name":"21159","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/21159"},{"name":"20060503 Quagga RIPD unauthenticated route table broadcast","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/432822/100/0/threaded"},{"name":"DSA-1059","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2006/dsa-1059"},{"name":"20221","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20221"},{"name":"20420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20420"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2223","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"SUSE-SR:2006:017","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2006_17_sr.html"},{"name":"USN-284-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/284-1/"},{"name":"quagga-ripv1-information-disclosure(26243)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26243"},{"name":"20782","refsource":"SECUNIA","url":"http://secunia.com/advisories/20782"},{"name":"20138","refsource":"SECUNIA","url":"http://secunia.com/advisories/20138"},{"name":"20060503 Re: Quagga RIPD unauthenticated route injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/432823/100/0/threaded"},{"name":"20421","refsource":"SECUNIA","url":"http://secunia.com/advisories/20421"},{"name":"20060602-01-U","refsource":"SGI","url":"ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc"},{"name":"25224","refsource":"OSVDB","url":"http://www.osvdb.org/25224"},{"name":"RHSA-2006:0525","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2006-0525.html"},{"name":"20137","refsource":"SECUNIA","url":"http://secunia.com/advisories/20137"},{"name":"http://bugzilla.quagga.net/show_bug.cgi?id=261","refsource":"CONFIRM","url":"http://bugzilla.quagga.net/show_bug.cgi?id=261"},{"name":"1016204","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016204"},{"name":"19910","refsource":"SECUNIA","url":"http://secunia.com/advisories/19910"},{"name":"oval:org.mitre.oval:def:9985","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985"},{"name":"17808","refsource":"BID","url":"http://www.securityfocus.com/bid/17808"},{"name":"RHSA-2006:0533","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2006-0533.html"},{"name":"GLSA-200605-15","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml"},{"name":"21159","refsource":"SECUNIA","url":"http://secunia.com/advisories/21159"},{"name":"20060503 Quagga RIPD unauthenticated route table broadcast","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/432822/100/0/threaded"},{"name":"DSA-1059","refsource":"DEBIAN","url":"http://www.debian.org/security/2006/dsa-1059"},{"name":"20221","refsource":"SECUNIA","url":"http://secunia.com/advisories/20221"},{"name":"20420","refsource":"SECUNIA","url":"http://secunia.com/advisories/20420"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-2223","datePublished":"2006-05-05T19:00:00.000Z","dateReserved":"2006-05-05T00:00:00.000Z","dateUpdated":"2024-08-07T17:43:28.938Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-05-05 19:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:quagga:quagga:0.98.5:*:*:*:*:*:*:*","matchCriteriaId":"D6ADB9F6-B519-45D0-966F-F095372FBB49"},{"vulnerable":true,"criteria":"cpe:2.3:a:quagga:quagga:0.99.3:*:*:*:*:*:*:*","matchCriteriaId":"9E1B30CC-478C-4BD1-AF4C-D126B8CCE8D6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2223","Ordinal":"1","Title":"CVE-2006-2223","CVE":"CVE-2006-2223","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2223","Ordinal":"1","NoteData":"RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.","Type":"Description","Title":"CVE-2006-2223"},{"CveYear":"2006","CveId":"2223","Ordinal":"2","NoteData":"2006-05-05","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2223","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}