« Back to list

CVE-2006-4021

Status: ModifiedLow (2.6)—

The cryptographic module in ScatterChat 1.0.x allows attackers to identify patterns in large numbers of messages by identifying collisions using a birthday attack on the custom padding mechanism for ECB mode encryption.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2006-4021",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-08-17T21:04:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/1396",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.scatterchat.com/advisories/2006-01_non_tech.html",
      "tags": [
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.scatterchat.com/advisories/2006-01_tech.html",
      "tags": [
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443038/100/100/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19485",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1396",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.scatterchat.com/advisories/2006-01_non_tech.html",
      "tags": [
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.scatterchat.com/advisories/2006-01_tech.html",
      "tags": [
        "Vendor Advisory",
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443038/100/100/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19485",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The cryptographic module in ScatterChat 1.0.x allows attackers to identify patterns in large numbers of messages by identifying collisions using a birthday attack on the custom padding mechanism for ECB mode encryption."
    },
    {
      "lang": "es",
      "value": "El módulo criptográfico en ScatterChat 1.0.x permite a atacantes identificar patrones en gran número de mensajes mediante la identificación de colisiones utilizando un \"ataque de cumpleaños\" (birthday attack) en el mecanismo de relleno específico para el modo ECB de cifrado."
    }
  ],
  "lastModified": "2026-06-16T22:28:16.727",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:scatterchat:scatterchat:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "798E948D-3CF2-48DD-B490-13EC82F20D1C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "This vulnerability will be addressed in the following future product release:\r\nScatterChat, ScatterChat, 2.0"
}