MEDIUM · 5.0

CVE-2005-0356

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoo...

Vulnerability Description

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoAgent DesktopAll versions
CiscoE-Mail ManagerAll versions
CiscoEmergency Responder1.1
CiscoIntelligent Contact Manager5.0
CiscoInteractive Voice ResponseAll versions
CiscoIp Contact Center EnterpriseAll versions
CiscoIp Contact Center ExpressAll versions
CiscoMeetingplaceAll versions
CiscoPersonal Assistant1.3\(1\)
CiscoRemote Monitoring Suite OptionAll versions
CiscoSecure Access Control Server2.0
CiscoSupport ToolsAll versions
CiscoWeb Collaboration OptionAll versions
HitachiAlaxalaax
CiscoCall Manager1.0
CiscoUnity Server2.0
CiscoMgx 82301.2.10
CiscoMgx 82501.2.10
CiscoCiscoworks Access Control List Manager1.5
CiscoCiscoworks Common Management Foundation2.0

References

FAQ

What is CVE-2005-0356?

CVE-2005-0356 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoo...

How severe is CVE-2005-0356?

CVE-2005-0356 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0356?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Agent Desktop, Cisco E-Mail Manager, Cisco Emergency Responder, Cisco Intelligent Contact Manager, Cisco Interactive Voice Response.