← Back

CVE-2023-6534

nvd nist
Published: Dec 13, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers.  This could allow a malicious actor to execute a denial-of-service attack against hosts behind the firewall.

Affected (23)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 12.4
Version 12.4 p1
Version 12.4 p2
Version 12.4 p3
Version 12.4 p4
Version 12.4 p5
Version 12.4 p6
Version 12.4 p7
Version 12.4 p8
Version 12.4 rc2-p1
Version 12.4 rc2-p2
Version 13.2
Version 13.2 p1
Version 13.2 p2
Version 13.2 p3
Version 13.2 p4
Version 13.2 p5
Version 13.2 p6
Version 14.0
Version 14.0 beta5
Version 14.0 p1
Version 14.0 rc3
Version 14.0 rc4-p1

References (4)

Source: secteam@freebsd.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.