CVE-2019-18625
Last modified
CVE-2019-18625 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. EPSS estimates a 1.71% chance of exploitation in the next 30 days.
Description
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP Timestamp option. The client will ignore the RST ACK and the FIN ACK packets because of the bad TCP Timestamp option. Both linux and windows client are ignoring the injected packets.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oisf | Suricata | 5.0.0 |
| Debian | Debian Linux | 8.0 |
References
- https://github.com/OISF/suricata/commit/9f0294fadca3dcc18c919424242a41e01f3e8318Patch, Third Party Advisory
- https://github.com/OISF/suricata/commit/ea0659de7640cf6a51de5bbd1dbbb0414e4623a0Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00032.htmlMailing List, Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/3286Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/3395Third Party Advisory
- https://github.com/OISF/suricata/commit/9f0294fadca3dcc18c919424242a41e01f3e8318Patch, Third Party Advisory
- https://github.com/OISF/suricata/commit/ea0659de7640cf6a51de5bbd1dbbb0414e4623a0Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00032.htmlMailing List, Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/3286Third Party Advisory
- https://redmine.openinfosecfoundation.org/issues/3395Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-18625?
How severe is CVE-2019-18625?
How do I fix CVE-2019-18625?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-18618Incorrect access control in the firmware of Synaptics VFS75x…6
- CVE-2019-18619Incorrect parameter validation in the synaTee component of S…7.8
- CVE-2019-1862A vulnerability in the web-based user interface (Web UI) of …7.2
- CVE-2019-18622An issue was discovered in phpMyAdmin before 4.9.2. A crafte…9.8
- CVE-2019-18623Escalation of privileges in EnergyCAP 7 through 7.5.6 allows…9.8
- CVE-2019-18624Opera Mini for Android allows attackers to bypass intended r…9.8
- CVE-2019-18626Harris Ormed Self Service before 2019.1.4 allows an authenti…4.3
- CVE-2019-18628Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035…4.9
- CVE-2019-18629Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035…8.1
- CVE-2019-1863A vulnerability in the web-based management interface of Cis…8.1
- CVE-2019-18630On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8…7.5
- CVE-2019-18631The Windows component of Centrify Authentication and Privile…7.8
Are you affected by CVE-2019-18625?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
