CVE-2005-0356
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD
Description
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
Affected (296)
Products: Cisco: Agent Desktop, Call Manager, E Mail Manager, Emergency Responder, Intelligent Contact Manager, Interactive Voice Response, Ip Contact Center Enterprise, Ip Contact Center Express, Meetingplace, Mgx 8230, Mgx 8250, Personal Assistant, Remote Monitoring Suite Option, Secure Access Control Server, Support Tools, Unity Server, Web Collaboration Option, Ciscoworks 1105 Hosting Solution Engine, Ciscoworks 1105 Wireless Lan Solution Engine, Ciscoworks Access Control List Manager, Ciscoworks Cd1, Ciscoworks Common Management Foundation, Ciscoworks Common Services, Ciscoworks Lms, Ciscoworks Vpn Security Management Solution, Ciscoworks Windows, Ciscoworks Windows Wug, Conference Connection, Content Services Switch 11000, Content Services Switch 11050, Content Services Switch 11150, Content Services Switch 11500, Content Services Switch 11501, Content Services Switch 11503, Content Services Switch 11506, Content Services Switch 11800, Webns, Aironet Ap1200, Aironet Ap350, Sn 5420 Storage Router, Sn 5420 Storage Router Firmware, Sn 5428 Storage Router · Hitachi: Alaxala, Gr3000, Gr4000, Gs4000 · Freebsd: Freebsd · +6 more
Show all products
Cisco: Agent Desktop, Call Manager, E Mail Manager, Emergency Responder, Intelligent Contact Manager, Interactive Voice Response, Ip Contact Center Enterprise, Ip Contact Center Express, Meetingplace, Mgx 8230, Mgx 8250, Personal Assistant, Remote Monitoring Suite Option, Secure Access Control Server, Support Tools, Unity Server, Web Collaboration Option, Ciscoworks 1105 Hosting Solution Engine, Ciscoworks 1105 Wireless Lan Solution Engine, Ciscoworks Access Control List Manager, Ciscoworks Cd1, Ciscoworks Common Management Foundation, Ciscoworks Common Services, Ciscoworks Lms, Ciscoworks Vpn Security Management Solution, Ciscoworks Windows, Ciscoworks Windows Wug, Conference Connection, Content Services Switch 11000, Content Services Switch 11050, Content Services Switch 11150, Content Services Switch 11500, Content Services Switch 11501, Content Services Switch 11503, Content Services Switch 11506, Content Services Switch 11800, Webns, Aironet Ap1200, Aironet Ap350, Sn 5420 Storage Router, Sn 5420 Storage Router Firmware, Sn 5428 Storage Router · Hitachi: Alaxala, Gr3000, Gr4000, Gs4000 · Freebsd: Freebsd · Microsoft: Windows 2000, Windows 2003 Server, Windows Xp · Nortel: 7220 Wlan Access Point, 7250 Wlan Access Point, Business Communications Manager, Callpilot, Contact Center, Ethernet Routing Switch 1612, Ethernet Routing Switch 1624, Ethernet Routing Switch 1648, Optical Metro 5000, Optical Metro 5100, Optical Metro 5200, Succession Communication Server 1000, Survivable Remote Gateway, Universal Signaling Point · Openbsd: Openbsd · Alaxala: Alaxala Networks · F5: Tmos · Yamaha: Rt105, Rt250i, Rt300i, Rt57i, Rtv700, Rtx1000, Rtx1100, Rtx1500, Rtx2000
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 1.0 | |
| All versions | |
| Version 1.1 | |
| Version 5.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 1.2.10 | |
| Version 1.2.10 | |
| Version 1.3(1) | |
| All versions | |
| Version 2.0 | |
| All versions | |
| Version 2.0 | |
| All versions | |
| Version ax |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| Version 1.5 | |
| Version 1st | |
| Version 2.0 | |
| Version 2.2 | |
| Version 1.3 | |
| All versions | |
| All versions | |
| All versions | |
| Version 1.1(1) | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 7.10_(05.07)s | |
| Version 1.1.5.1 | |
| All versions | |
| Version enterprise | |
| All versions | |
| All versions | |
| All versions | |
| Version 1000 | |
| Version 200i | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 1.0 | |
| Version 5200 | |
| Version 3.0 | |
| Version ax5400s |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| Version 1.1.3 | |
| Version 2-3.3.1-k9 | |
| Version 4.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (22)
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc (unsafe URL)
Source: cret@cert.org
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt (unsafe URL)
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Vendor Advisory
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.