Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84r6-pwmm-h2fw

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

EPSS

Процентиль: 25%
0.00089
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-940

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров Siemens SIMATIC S7, связанная с недостаточной проверкой источника канала связи, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 25%
0.00089
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-940