VDB
CVE-2005-0356
CVE-2005-0356
PUBLISHED
CVSS 5 MEDIUM
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
EPSS 81.53% · 99.2th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
81.53%
99.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nortel | business_communications_manager | 1000, 400, 200 |
| cisco | content_services_switch_11500 | |
| cisco | content_services_switch_11050 | |
| nortel | ethernet_routing_switch_1648 | |
| cisco | mgx_8230 | 1.2.11, 1.2.10 |
| cisco | ciscoworks_1105_wireless_lan_solution_engine | |
| cisco | content_services_switch_11506 | |
| cisco | ip_contact_center_enterprise | |
| hitachi | gr3000 | |
| openbsd | openbsd | 3.3, 3.2, 3.1 |
| yamaha | rtx1000 | |
| cisco | content_services_switch_11150 | |
| cisco | content_services_switch_11800 | |
| cisco | interactive_voice_response | |
| cisco | ciscoworks_cd1 | 1st, *, 2nd |
| cisco | secure_access_control_server | 2.3, 2.6, 2.6.3 |
| cisco | ciscoworks_windows_wug | |
| yamaha | rtx1100 | |
| n/a | n/a | n/a |
| cisco | web_collaboration_option |
…and 57 more
Timeline
- Apr 18, 2005 CVE Published
- May 18, 2005 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 20, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- tcp-ip-timestamp-dos(20635) vdb
- 15393 third-party-advisory
- VU#637934 third-party-advisory
- 15417 third-party-advisory
- 18662 third-party-advisory
- SCOSA-2005.64 vendor-advisory
- FreeBSD-SA-05:15 vendor-advisory
- 13676 vdb
- 20050518 Vulnerability in a Variant of the TCP Timestamps Option vendor-advisory
- 18222 third-party-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm url
- https://nvd.nist.gov/vuln/detail/CVE-2005-0356 advisory
- http://secunia.com/advisories/15417 url