« Volver al listado

CVE-2006-3894

Estado: ModificadaMedia (5)—

The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3894",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-05-22T19:30:00.000",
  "references": [
    {
      "url": "http://jvn.jp/cert/JVNVU%23754281/index.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://osvdb.org/35338",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/25343",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/25364",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/25399",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c5d.shtml",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/754281",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24104",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1018095",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1908",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1909",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1945",
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34430",
      "source": "cret@cert.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5778",
      "source": "cret@cert.org"
    },
    {
      "url": "https://secure-support.novell.com/KanisaPlatform/Publishing/97/3590033_f.SAL_Public.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://jvn.jp/cert/JVNVU%23754281/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/35338",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25343",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25364",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25399",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c5d.shtml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/754281",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24104",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1018095",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1908",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1909",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1945",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34430",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5778",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://secure-support.novell.com/KanisaPlatform/Publishing/97/3590033_f.SAL_Public.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other products, allows remote attackers to cause a denial of service via malformed ASN.1 objects."
    },
    {
      "lang": "es",
      "value": "Las librerías RSA Crypto-C anterior a 6.3.1 y Cert-C anterior a 2.8, usadas por RSA BSAFE, múltiples productos Cisco, y otros productos, permite a atacantes remotos provocar una denegación de servicio mediante objetos ASN.1 mal formados."
    }
  ],
  "lastModified": "2026-06-16T22:28:01.827",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:bsafe_cert-c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0249AD93-0A32-4227-AD83-88BE21009FF5",
              "versionEndIncluding": "2.7"
            },
            {
              "criteria": "cpe:2.3:a:dell:bsafe_crypto-c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D00E07EA-40F3-47D5-B31D-ECE03172D76C",
              "versionEndIncluding": "6.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}