CVE-2004-0230
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 80.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 80.29% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- juniper/junos · microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows server 2003 · microsoft/windows xp · oracle/solaris · openpgp/openpgp · mcafee/network data loss prevention · netbsd/netbsd · xinuos/openserver · xinuos/unixware
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.ascBroken Link, Third Party Advisory
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txtBroken Link, Third Party Advisory
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txtBroken Link, Third Party Advisory
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txtBroken Link, Third Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.ascBroken Link, Third Party Advisory
- http://kb.juniper.net/JSA10638Third Party Advisory
- http://marc.info/?l=bugtraq&m=108302060014745&w=2Mailing List
- http://marc.info/?l=bugtraq&m=108506952116653&w=2Mailing List
- http://secunia.com/advisories/11440Broken Link, Permissions Required, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/11458Broken Link, Permissions Required, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/22341Broken Link, Permissions Required, Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtmlBroken Link
- http://www.kb.cert.org/vuls/id/415294Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlPatch, Third Party Advisory
- http://www.osvdb.org/4030Broken Link
- http://www.securityfocus.com/archive/1/449179/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/10183Exploit, Third Party Advisory, VDB Entry
- http://www.uniras.gov.uk/vuls/2004/236929/index.htmBroken Link
- http://www.us-cert.gov/cas/techalerts/TA04-111A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/3983Broken Link, Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-064Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15886Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10053Broken Link, Patch, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2689Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A270Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3508Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4791Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5711Broken Link
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.ascBroken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.