Denial of Service Vulnerability in Cisco IOS and VPN 3000 Concentrators
CVE-2006-3906

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
27 July 2006

Summary

The Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco's IOS, VPN 3000 Concentrators, and PIX firewalls, is susceptible to a Denial of Service (DoS) attack. Remote attackers can exploit this vulnerability by sending a flood of IKE Phase-1 packets that exceed the session expiration rate, leading to resource exhaustion. This issue highlights a fundamental design weakness in the IKE version 1 protocol, making it a potential concern for other vendors and implementations that utilize this protocol.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.