CVE-2006-2924: Medium severity ingate ingate siparator vulnerability
Published Jun 9, 2006
·Updated
Ingate Firewall in the SIP module before 4.4.1 and SIParator before 4.4.1, when TLS is enabled or when SSL/TLS is enabled in the web server, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake.
Affected Software
4 affected components
Ingate Ingate SIParator=4.3.4
Ingate Ingate Firewall<=4.4.0
Ingate Ingate Firewall=4.3.4
Ingate Ingate SIParator<=4.4.0
Remediation
Patch Available
Patch Available
Event History
Jun 9, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2924?
CVE-2006-2924 is considered a critical vulnerability due to its potential for remote denial of service attacks.
2
How can I mitigate CVE-2006-2924?
To mitigate CVE-2006-2924, upgrade Ingate Firewall or SIParator to version 4.4.1 or later.
3
What systems are affected by CVE-2006-2924?
CVE-2006-2924 affects Ingate Firewall versions before 4.4.1 and SIParator versions before 4.4.1.
4
What type of attack does CVE-2006-2924 allow?
CVE-2006-2924 allows remote attackers to perform denial of service attacks through crafted SSL/TLS handshakes.
5
Is CVE-2006-2924 related to SSL/TLS security?
Yes, CVE-2006-2924 exploits SSL/TLS vulnerabilities in the Ingate Firewall and SIParator.