CVE-2006-2224
Quagga Routing Software Suite < 0.99.3 - Unauthenticated Routing State Modification via RIPv1 RESPONSE Packets
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2224. PoCs published by Konstantin V. Gavrilenko.
AI-analyzed exploit summary This exploit leverages Quagga's failure to enforce authentication and protocol configuration, allowing remote attackers to inject arbitrary routes into the RIP routing table via a crafted UDP packet sent to port 520.
Description
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
Exploits (1)
This exploit leverages Quagga's failure to enforce authentication and protocol configuration, allowing remote attackers to inject arbitrary routes into the RIP routing table via a crafted UDP packet sent to port 520.