peter bassill · operator
$ cve CVE-2005-0356 JSON

CVE-2005-0356 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 82.8% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS82.76% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-31
Last modified2026-06-16

Affected (40)

VendorProduct
ciscoagent desktop
ciscocall manager
ciscociscoworks access control list manager
ciscociscoworks common management foundation
ciscociscoworks common services
ciscociscoworks lms
ciscociscoworks vpn security management solution
ciscociscoworks windows
ciscocontent services switch 11000
ciscocontent services switch 11050
ciscocontent services switch 11150
ciscocontent services switch 11500
ciscocontent services switch 11501
ciscocontent services switch 11503
ciscocontent services switch 11506
ciscocontent services switch 11800
ciscoe-mail manager
ciscoemergency responder
ciscointelligent contact manager
ciscointeractive voice response
ciscoip contact center enterprise
ciscoip contact center express
ciscomeetingplace
ciscomgx 8230
ciscomgx 8250
ciscopersonal assistant
ciscoremote monitoring suite option
ciscosecure access control server
ciscosupport tools
ciscounity server
ciscoweb collaboration option
ciscowebns
hitachialaxala
nortel7220 wlan access point
nortel7250 wlan access point
nortelbusiness communications manager
nortelcallpilot
nortelcontact center
nortelethernet routing switch 1612
nortelethernet routing switch 1624

Public exploits

SourceTitleDate
exploit-dbTCP TIMESTAMPS - Denial of Service2005-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD