Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-0230

74
FAUCET Score

CVE-2004-0230 describes a denial-of-service vulnerability in TCP implementations that utilize a large Window Size, making it easier for remote attackers to guess TCP sequence numbers. This allows an attacker to inject TCP RST packets, disrupting persistent connections in protocols like BGP. The vulnerability affects a wide range of products including Juniper, McAfee, Microsoft, NetBSD, and Oracle. Rated with a CVSS score of 5.0 (medium severity), the attack requires no authentication and has low attack complexity, leading to a partial denial of service. Its FAUCET Risk Score is 85/100, indicating a significant risk despite the medium CVSS score. While not listed in CISA's KEV catalog, multiple exploit proofs-of-concept are available on ExploitDB, suggesting the vulnerability is well-understood and exploitable. Despite this, there is no recorded community discussion or media coverage, indicating a lack of public attention or active widespread exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
11.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:11.4:-:*:*:*:*:*:*
11.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:11.4:r1:*:*:*:*:*:*
11.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:11.4:r10:*:*:*:*:*:*
11.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:11.4:r2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
80.29%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-942 · Apr 17, 2005
This CVE's current EPSS score of 0.8029 is in the 100th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

oraclepatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2004-0230

CVE-2004-0230

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc
Broken LinkThird Party Advisory
ftp.sco.com / pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt
Broken LinkThird Party Advisory
ftp.sco.com / pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt
Broken LinkThird Party Advisory
ftp.sco.com / pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt
Broken LinkThird Party Advisory
patches.sgi.com / support/free/security/advisories/20040403-01-A.asc
Broken LinkThird Party Advisory
kb.juniper.net / JSA10638
Third Party Advisory
marc.info
Mailing List
marc.info
Mailing List
docs.microsoft.com / en-us/security-updates/securitybulletins/2005/ms05-019
Third Party Advisory
docs.microsoft.com / en-us/security-updates/securitybulletins/2006/ms06-064
Third Party Advisory
secunia.com / advisories/11440
Broken LinkPermissions RequiredThird Party AdvisoryVDB Entry
secunia.com / advisories/11458
Broken LinkPermissions RequiredThird Party AdvisoryVDB Entry
secunia.com / advisories/22341
Broken LinkPermissions RequiredThird Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/15886
Third Party Advisory
kc.mcafee.com / corporate/index
Broken LinkPatchThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2689
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A270
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3508
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4791
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5711
Broken Link
cisco.com / warp/public/707/cisco-sa-20040420-tcp-ios.shtml
Broken Link
kb.cert.org / vuls/id/415294
Third Party AdvisoryUS Government Resource
oracle.com / technetwork/topics/security/cpujan2015-1972971.html
PatchThird Party Advisory
osvdb.org / 4030
Broken Link
securityfocus.com / archive/1/449179/100/0/threaded
Broken Link
securityfocus.com / bid/10183
ExploitThird Party AdvisoryVDB Entry
uniras.gov.uk / vuls/2004/236929/index.htm
Broken Link
us-cert.gov / cas/techalerts/TA04-111A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2006/3983
Broken LinkPermissions Required