Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

TCP Vulnerabilities in Multiple IOS-Based Cisco Products

cisco-sa-20040420-tcp-ios · NA · Published · Updated

A vulnerability in the Transmission Control Protocol (TCP) specification (RFC793) has been discovered by an external researcher. The successful exploitation enables an adversary to reset any established TCP connection in a much shorter time than was previously discussed publicly. Depending on the application, the connection may get automatically re-established. In other cases, a user will have to repeat the action (for example, open a new Telnet or SSH session). Depending upon the attacked protocol, a successful attack may have additional consequences beyond terminated connection which must be considered. This attack vector is only applicable to the sessions which are terminating on a device (such as a router, switch, or computer) and not to the sessions that are only passing through the device (for example, transit traffic that is being routed by a router). In addition, this attack vector does not directly compromise data integrity or confidentiality. All Cisco products which contain a TCP stack are susceptible to this vulnerability. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040420-tcp-ios, and it describes this vulnerability as it applies to Cisco products that run Cisco IOS�� software. A companion advisory that describes this vulnerability for products that do not run Cisco IOS software is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040420-tcp-nonios.

Cisco advisory · CSAF JSON

Workarounds

No workaround information imported yet.

CVEsCVE-2004-0230
Cisco Bug IDsNA
CVSS ScoreBase NA
Product Names From Source
NA, Cisco Cache Engine, Cisco Catalyst 1900/2820, Cisco Catalyst WS-X6608, Cisco Content Distribution Manager (CDM), Cisco Content Engine, Cisco Content Router, Cisco Content Services Switch (CSS), Cisco Content Switching Module (CSM), Cisco Element Management Framework (Cisco EMF), Cisco Firewall Services Module (FWSM), Cisco GSS Global Site Selector, Cisco IP phone, Cisco Intelligent Contact Manager (ICM), Cisco Intrusion Detection System (IDS), Cisco LocalDirector, Cisco MDS SAN-OS Software, Cisco Optical Networking Systems (ONS), Cisco PIX Firewall Software, Cisco Secure Access Control Server (ACS) for UNIX, Cisco Secure Access Control Server (ACS) for Windows, Cisco VG248 Analog Phone Gateway, Cisco VPN 3000 Series Concentrator, Cisco VPN 5000 Series Concentrator, Cisco WAN Manager for AIX, Cisco WAN Switching Software, Cisco WebNS, CiscoWorks Hosting Solution Engine (HSE), CiscoWorks Wireless LAN Solution Engine (WLSE), Cisco Unified Communications Manager

Related Products

Product CVE Evidence
CiscoWorks Wireless LAN Solution Engine (WLSE) CVE-2004-0230 Cisco OpenVuln
CiscoWorks Hosting Solution Engine (HSE) CVE-2004-0230 Cisco OpenVuln
Cisco WebNS CVE-2004-0230 Cisco OpenVuln
Cisco WAN Switching Software CVE-2004-0230 Cisco OpenVuln
Cisco WAN Manager for AIX CVE-2004-0230 Cisco OpenVuln
Cisco WAN Manager CVE-2004-0230 Cisco OpenVuln
Cisco VPN 5000 Series Concentrator CVE-2004-0230 Cisco OpenVuln
Cisco VPN 3000 Series Concentrator CVE-2004-0230 Cisco OpenVuln
Cisco VG248 Analog Phone Gateway CVE-2004-0230 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2004-0230 Cisco OpenVuln
Cisco Secure Access Control Server (ACS) for Windows CVE-2004-0230 Cisco OpenVuln
Cisco Secure Access Control Server (ACS) for UNIX CVE-2004-0230 Cisco OpenVuln
Cisco PIX Firewall Software CVE-2004-0230 Cisco OpenVuln
Cisco PIX Firewall CVE-2004-0230 Cisco OpenVuln
Cisco Optical Networking Systems (ONS) CVE-2004-0230 Cisco OpenVuln
Cisco MDS SAN-OS Software CVE-2004-0230 Cisco OpenVuln
Cisco LocalDirector CVE-2004-0230 Cisco OpenVuln
Cisco Intrusion Detection System (IDS) CVE-2004-0230 Cisco OpenVuln
Cisco Intelligent Contact Manager (ICM) CVE-2004-0230 Cisco OpenVuln
Cisco IP phone CVE-2004-0230 Cisco OpenVuln
Cisco IOS CVE-2004-0230 Cisco OpenVuln
Cisco GSS Global Site Selector CVE-2004-0230 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2004-0230 Cisco OpenVuln
Cisco Element Management Framework (Cisco EMF) CVE-2004-0230 Cisco OpenVuln
Cisco Content Switching Module (CSM) CVE-2004-0230 Cisco OpenVuln
Cisco Content Services Switch (CSS) CVE-2004-0230 Cisco OpenVuln
Cisco Content Router CVE-2004-0230 Cisco OpenVuln
Cisco Content Engine CVE-2004-0230 Cisco OpenVuln
Cisco Content Distribution Manager (CDM) CVE-2004-0230 Cisco OpenVuln
Cisco Catalyst WS-X6608 CVE-2004-0230 Cisco OpenVuln
Cisco Catalyst 1900/2820 CVE-2004-0230 Cisco OpenVuln
Cisco Cache Engine CVE-2004-0230 Cisco OpenVuln