SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-1649

The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source…

MEDIUM 5.0EPSS 21.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 21.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
21.78% probability · 97th percentile
CISA KEV
Not listed
Affected
microsoft/windows 2003 server · microsoft/windows xp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.