peter bassill · operator
$ cve CVE-2011-3188 JSON

CVE-2011-3188

9.1
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS5.03% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploitnone known
Published2012-05-24
Last modified2026-06-16

Affected (15)

VendorProduct
f5arx
f5big-ip access policy manager
f5big-ip analytics
f5big-ip application security manager
f5big-ip edge gateway
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip protocol security module
f5big-ip wan optimization manager
f5big-ip webaccelerator
f5enterprise manager
f5firepass
linuxlinux kernel
redhatenterprise linux

References

→ the Explorer  ·  watch your stack  ·  NVD