VDB

GCVE-110-CERTCC-2001-498440

GCVE-110-CERTCC-2001-498440
Advisory PublishedCVSS 5.8/10
Vulnetix · Advisory published March 12, 2001
Attacks against TCP initial sequence number generation have been discussed for some time now. It has long been recognized that the ability to know or predict ISNs can lead to TCP connection hijacking or spoofing. What was not previously illustrated was just how predictable one commonly-used method of randomizing new connection ISNs is in some modern TCP/IP implementations.

Risk Scores

CVSS 2.0
5.8/10
Medium · AV:N/AC:M/Au:N/C:P/I:N/A:P
certcc-cam
certcc-cam
impact15population20exploitation0widely_known10score_current15.1875ease_of_exploitation5
certcc-vrda
certcc-vrda
d1_impact2d1_population4d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score4.8remediation_levelOFreport_confidenceCenvironmental_score3.57084963766125target_distributionMenvironmental_vectorCDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›