CVE-2005-0356
published 2005-05-31CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a…
PriorityP337medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
82.76%
99.6th percentile
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
Affected
180 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alaxala | alaxala_networks | — | — |
| alaxala | alaxala_networks | — | — |
| alaxala | alaxala_networks | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | ciscoworks_access_control_list_manager | — | — |
| cisco | ciscoworks_access_control_list_manager | — | — |
| cisco | ciscoworks_cd1 | — | — |
| cisco | ciscoworks_cd1 | — | — |
| cisco | ciscoworks_cd1 | — | — |
| cisco | ciscoworks_cd1 | — | — |
| cisco | ciscoworks_cd1 | — | — |
| cisco | ciscoworks_common_management_foundation | — | — |
| cisco | ciscoworks_common_management_foundation | — | — |
| cisco | ciscoworks_common_management_foundation | — | — |
| cisco | ciscoworks_common_services | — | — |
| cisco | ciscoworks_lms | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandsend_tcp(sock, saddr, daddr, sport, dport, seq, ts) || send_tcp(sock, saddr, daddr, sport, dport, seq, op(ts)) || send_tcp(sock, saddr, daddr, sport, dport, op(seq), ts) || send_tcp(sock, saddr, daddr, sport, dport, op(seq), op(ts))↗
- →Look for raw TCP packets (IPPROTO_RAW) with IP_HDRINCL set, carrying TCP TIMESTAMP options (NOP, NOP, TIMESTAMP, length=10) with th_flags=0 (no SYN/FIN/ACK/RST) and th_ack=0, which is abnormal for mid-session traffic and characteristic of this exploit. ↗
- ·This vulnerability only affects TCP implementations that have both PAWS (Protection Against Wrapped Sequence Numbers) and the TCP timestamps option enabled. Disabling TCP timestamps mitigates the attack. ↗
- ·Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2 kernel packages are NOT affected; detection/patching efforts should focus on other OS/kernel versions. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6gj-g9qf-3c55: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus
ghsa_unreviewed·2022-05-03
CVE-2005-0356 [MEDIUM] GHSA-r6gj-g9qf-3c55: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
Red Hat
CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus
vendor_redhat·CVSS 5.0
CVE-2005-0356 [MEDIUM] CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to caus
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
Statement: Not vulnerable. This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
No detection rules found.
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.ascftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txthttp://secunia.com/advisories/15393http://secunia.com/advisories/15417/http://secunia.com/advisories/18222http://secunia.com/advisories/18662http://support.avaya.com/elmodocs2/security/ASA-2006-032.htmhttp://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtmlhttp://www.kb.cert.org/vuls/id/637934http://www.securityfocus.com/bid/13676https://exchange.xforce.ibmcloud.com/vulnerabilities/20635ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.ascftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txthttp://secunia.com/advisories/15393http://secunia.com/advisories/15417/http://secunia.com/advisories/18222http://secunia.com/advisories/18662http://support.avaya.com/elmodocs2/security/ASA-2006-032.htmhttp://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtmlhttp://www.kb.cert.org/vuls/id/637934http://www.securityfocus.com/bid/13676https://exchange.xforce.ibmcloud.com/vulnerabilities/20635
2005-05-31
Published