« Volver al listado

CVE-2006-0997

Estado: ModificadaMedia (5)—

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-0997",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-03-23T11:06:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/19324",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1015799",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/24046",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/17176",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1043",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25380",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/19324",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1015799",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/24046",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/17176",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1043",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25380",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic."
    }
  ],
  "lastModified": "2026-06-16T22:21:49.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:novell:open_enterprise_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1DA33CB-1F9D-4042-BD23-1E41A6079511"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D328A81E-DC60-4B67-B707-F0AD9A6F48E2"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CEB9CEA-9245-490F-88F6-EFD23B11A19B"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp1.1a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0669D0E2-AB83-44AE-A87C-C7EB7AA2953A"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp1.1b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "062E2A9A-CF88-4844-B5A1-7418722087D9"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F8E031C-CE1F-410F-8F32-B3E33719C498"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87F80FDC-7851-4EA8-BC7D-87B85C6BB93C"
            },
            {
              "criteria": "cpe:2.3:o:novell:netware:6.5:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C3AB68F-1D78-4217-9C56-B1B25F62FF38"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}