CVE-2005-1649 is a denial-of-service vulnerability affecting Windows XP SP2 and Windows 2003 Server SP1 when IPv6 support is enabled and the firewall is off. It allows remote attackers to consume CPU resources by sending a specially crafted TCP SYN packet with identical source and destination addresses and ports, a reoccurrence of the "Land" attack. With a CVSS score of 5.0, it is a network-based attack requiring low complexity, resulting in partial availability impact. While there is an ExploitDB entry, there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
datacenter_64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:* | ||
enterpriseCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:* | ||
enterpriseCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:* | ||
enterprise_64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:* | ||
enterprise_64-bitCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.