CVE-2005-3675
The Transmission Control Protocol (TCP) allows remote attackers to cause a denial of service (bandwidth consumption) by sending ACK messages for packets that have not yet been received (optimistic ACKs), which can cause the sender to increase its…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Transmission Control Protocol (TCP) allows remote attackers to cause a denial of service (bandwidth consumption) by sending ACK messages for packets that have not yet been received (optimistic ACKs), which can cause the sender to increase its transmission rate until it fills available bandwidth.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 2.32% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- tcp/tcp
- Source
- cve@mitre.org
References
- http://www.cs.umd.edu/~capveg/optack/optack-extended.pdf
- http://www.kb.cert.org/vuls/id/102014Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/15468/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23055
- http://www.cs.umd.edu/~capveg/optack/optack-extended.pdf
- http://www.kb.cert.org/vuls/id/102014Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/15468/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23055
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.