CVE-2006-5179
Estado: ModificadaMedia (5.4)—
Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification, a related issue to CVE-2006-2940.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.76%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5179",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-10-10T04:06:00.000",
"references": [
{
"url": "http://secunia.com/advisories/22206",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.uniras.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3859",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/22206",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.uniras.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3859",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) \"public exponent\" or (2) \"public modulus\" values in X.509 certificates that require extra time to process when using RSA signature verification, a related issue to CVE-2006-2940."
},
{
"lang": "es",
"value": "Intoto iGateway VPN y iGateway SSL-VPN permite a un atacante dependiente del contexto provocar denegación de servicio (consumo de CPU) a través de llavés públicas parásitas con un gran \"expoenente público\" o (2) valores \"módulo público\" en certificados X.509 que requieren tiempo extra para proceder con la verificación de la firma de RSA, un tema relacionado con CVE-2006-2940."
}
],
"lastModified": "2026-06-16T22:30:40.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:intoto:igateway_ssl-vpn:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB142A4C-E7B6-43D8-A376-32C6A77FB7BF"
},
{
"criteria": "cpe:2.3:h:intoto:igateway_vpn:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB91D1AA-041F-4BF2-B9FE-EFF3BC0E5266"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "It is reported that a patch may be obtained by contacting Intoto at the following email address: support@intoto.com"
}