{"api_version":"1","generated_at":"2026-07-23T08:34:09+00:00","cve":"CVE-2006-4650","urls":{"html":"https://cve.report/CVE-2006-4650","api":"https://cve.report/api/cve/CVE-2006-4650.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4650","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4650"},"summary":{"title":"CVE-2006-4650","description":"Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-09-09 00:04:00","updated_at":"2018-10-17 21:38:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://securitytracker.com/id?1016799","name":"1016799","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Cisco IOS GRE Parsing Error May Let Remote Users Inject Packets","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/28590","name":"28590","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/21783","name":"21783","refsource":"SECUNIA","tags":[],"title":"Cisco IOS GRE Decapsulation Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5713","name":"oval:org.mitre.oval:def:5713","refsource":"OVAL","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28786","name":"cisco-ios-gre-acl-bypass(28786)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.phenoelit.de/stuff/CiscoGRE.txt","name":"http://www.phenoelit.de/stuff/CiscoGRE.txt","refsource":"MISC","tags":["Vendor Advisory"],"title":"PHENOELIT","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/445322/100/0/threaded","name":"20060906 Cisco IOS GRE issue","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1526","name":"1526","refsource":"SREASON","tags":[],"title":"SecurityReason - Cisco IOS GRE issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/en/US/tech/tk827/tk369/tsd_technology_security_response09186a008072cd7b.html","name":"20060906 Cisco IOS GRE Decapsulation Vulnerability","refsource":"CISCO","tags":[],"title":"Cisco Security Response to: Cisco IOS GRE Decapsulation Vulnerability  [IP Tunneling] - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3502","name":"ADV-2006-3502","refsource":"VUPEN","tags":[],"title":"Webmail- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19878","name":"19878","refsource":"BID","tags":[],"title":"Cisco IOS Multiple GRE Source Routing Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4650","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4650","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4650","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4650","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3502","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3502"},{"name":"1016799","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016799"},{"name":"28590","refsource":"OSVDB","url":"http://www.osvdb.org/28590"},{"name":"20060906 Cisco IOS GRE issue","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/445322/100/0/threaded"},{"name":"http://www.phenoelit.de/stuff/CiscoGRE.txt","refsource":"MISC","url":"http://www.phenoelit.de/stuff/CiscoGRE.txt"},{"name":"21783","refsource":"SECUNIA","url":"http://secunia.com/advisories/21783"},{"name":"1526","refsource":"SREASON","url":"http://securityreason.com/securityalert/1526"},{"name":"19878","refsource":"BID","url":"http://www.securityfocus.com/bid/19878"},{"name":"20060906 Cisco IOS GRE Decapsulation Vulnerability","refsource":"CISCO","url":"http://www.cisco.com/en/US/tech/tk827/tk369/tsd_technology_security_response09186a008072cd7b.html"},{"name":"oval:org.mitre.oval:def:5713","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5713"},{"name":"cisco-ios-gre-acl-bypass(28786)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28786"}]}},"nvd":{"publishedDate":"2006-09-09 00:04:00","lastModifiedDate":"2018-10-17 21:38:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:ios:12.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:ios:12.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4650","Ordinal":"19986","Title":"CVE-2006-4650","CVE":"CVE-2006-4650","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4650","Ordinal":"1","NoteData":"Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4650","Ordinal":"2","NoteData":"2006-09-08","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4650","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}