CVE-2004-0230

UnknownEPSS 80.86%

Last modified

CVE-2004-0230 is a vulnerability of currently unknown severity. TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.. EPSS estimates a 80.86% chance of exploitation in the next 30 days.

Description

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Metrics

EPSS Probability
80.86%

99.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
JuniperJunos< 11.4
JuniperJunos11.4
JuniperJunos11.4r13S2
JuniperJunos11.4x27
JuniperJunos12.1
JuniperJunos12.1r
JuniperJunos12.1x44
JuniperJunos12.1x45
JuniperJunos12.1x46
JuniperJunos12.1x47
JuniperJunos12.2
JuniperJunos12.3
JuniperJunos13.1
JuniperJunos13.2
JuniperJunos13.3
MicrosoftWindows 2000All versionsSp3
MicrosoftWindows 98All versions
MicrosoftWindows 98seAll versions
MicrosoftWindows Server 2003All versions
MicrosoftWindows XpAll versions
OracleSolaris10
OracleSolaris11
OpenpgpOpenpgp2.6.2
McafeeNetwork Data Loss Prevention<= 8.6
McafeeNetwork Data Loss Prevention9.2.0
McafeeNetwork Data Loss Prevention9.2.1
McafeeNetwork Data Loss Prevention9.2.2
NetbsdNetbsd1.5
NetbsdNetbsd1.5.1
NetbsdNetbsd1.5.2
NetbsdNetbsd1.5.3
NetbsdNetbsd1.6
NetbsdNetbsd1.6.1
NetbsdNetbsd1.6.2
NetbsdNetbsd2.0
XinuosOpenserver5.0.6
XinuosOpenserver5.0.7
XinuosUnixware7.1.1
XinuosUnixware7.1.3

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2004-0230?
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
How severe is CVE-2004-0230?
Severity scoring for CVE-2004-0230 is pending analysis. The EPSS model estimates a 80.86% probability of exploitation in the next 30 days.
How do I fix CVE-2004-0230?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-0230?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST