CVE-2004-0230 describes a denial-of-service vulnerability in TCP implementations that utilize a large Window Size, making it easier for remote attackers to guess TCP sequence numbers. This allows an attacker to inject TCP RST packets, disrupting persistent connections in protocols like BGP. The vulnerability affects a wide range of products including Juniper, McAfee, Microsoft, NetBSD, and Oracle. Rated with a CVSS score of 5.0 (medium severity), the attack requires no authentication and has low attack complexity, leading to a partial denial of service. Its FAUCET Risk Score is 85/100, indicating a significant risk despite the medium CVSS score. While not listed in CISA's KEV catalog, multiple exploit proofs-of-concept are available on ExploitDB, suggesting the vulnerability is well-understood and exploitable. Despite this, there is no recorded community discussion or media coverage, indicating a lack of public attention or active widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:11.4:-:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:11.4:r1:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:11.4:r10:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:11.4:r2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.