{"api_version":"1","generated_at":"2026-07-23T11:12:03+00:00","cve":"CVE-2006-2711","urls":{"html":"https://cve.report/CVE-2006-2711","api":"https://cve.report/api/cve/CVE-2006-2711.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2711","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2711"},"summary":{"title":"CVE-2006-2711","description":"Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-05-31 22:02:00","updated_at":"2017-07-20 01:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.kb.cert.org/vuls/id/WDON-6QAQN6","name":"http://www.kb.cert.org/vuls/id/WDON-6QAQN6","refsource":"CONFIRM","tags":[],"title":"Secure Elements  Information for VU#346377","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20377","name":"20377","refsource":"SECUNIA","tags":[],"title":"Secure Elements Class 5 AVR Message Encryption Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26740","name":"c5evm-key-weak-encryption(26740)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016184","name":"1016184","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - C5 Enterprise Vulnerability Management Bugs Let Remote Users Access the System, Execute Arbitrary Code, Monitor Communications, and Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2068","name":"ADV-2006-2068","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/346377","name":"VU#346377","refsource":"CERT-VN","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#346377","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2711","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2711","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2711","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"secure_elements","cpe5":"class_5_enterprise_vulnerability_management","cpe6":"2.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2711","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"secure_elements","cpe5":"class_5_enterprise_vulnerability_management","cpe6":"2.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2711","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"c5evm-key-weak-encryption(26740)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26740"},{"name":"20377","refsource":"SECUNIA","url":"http://secunia.com/advisories/20377"},{"name":"http://www.kb.cert.org/vuls/id/WDON-6QAQN6","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/WDON-6QAQN6"},{"name":"1016184","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016184"},{"name":"VU#346377","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/346377"},{"name":"ADV-2006-2068","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2068"}]}},"nvd":{"publishedDate":"2006-05-31 22:02:00","lastModifiedDate":"2017-07-20 01:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:secure_elements:class_5_enterprise_vulnerability_management:2.8.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2711","Ordinal":"18031","Title":"CVE-2006-2711","CVE":"CVE-2006-2711","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2711","Ordinal":"1","NoteData":"Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2711","Ordinal":"2","NoteData":"2006-05-31","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2711","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}