CVE-2004-0230

UnknownEPSS 80.86%

Last modified

CVE-2004-0230 is a vulnerability of currently unknown severity. TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.. EPSS estimates a 80.86% chance of exploitation in the next 30 days.

Description

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Metrics

EPSS Probability
80.86%

99.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
JuniperJunos< 11.4—
JuniperJunos11.4—
JuniperJunos11.4r13S2
JuniperJunos11.4x27—
JuniperJunos12.1—
JuniperJunos12.1r—
JuniperJunos12.1x44—
JuniperJunos12.1x45—
JuniperJunos12.1x46—
JuniperJunos12.1x47—
JuniperJunos12.2—
JuniperJunos12.3—
JuniperJunos13.1—
JuniperJunos13.2—
JuniperJunos13.3—
MicrosoftWindows 2000All versionsSp3
MicrosoftWindows 98All versions—
MicrosoftWindows 98seAll versions—
MicrosoftWindows Server 2003All versions—
MicrosoftWindows XpAll versions—
OracleSolaris10—
OracleSolaris11—
OpenpgpOpenpgp2.6.2—
McafeeNetwork Data Loss Prevention<= 8.6—
McafeeNetwork Data Loss Prevention9.2.0—
McafeeNetwork Data Loss Prevention9.2.1—
McafeeNetwork Data Loss Prevention9.2.2—
NetbsdNetbsd1.5—
NetbsdNetbsd1.5.1—
NetbsdNetbsd1.5.2—
NetbsdNetbsd1.5.3—
NetbsdNetbsd1.6—
NetbsdNetbsd1.6.1—
NetbsdNetbsd1.6.2—
NetbsdNetbsd2.0—
XinuosOpenserver5.0.6—
XinuosOpenserver5.0.7—
XinuosUnixware7.1.1—
XinuosUnixware7.1.3—

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2004-0230?
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
How severe is CVE-2004-0230?
Severity scoring for CVE-2004-0230 is pending analysis. The EPSS model estimates a 80.86% probability of exploitation in the next 30 days.
How do I fix CVE-2004-0230?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2004

Are you affected by CVE-2004-0230?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST