TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP
Published May 5, 2004
5.0
MEDIUMCVSS 2.0
EPSS 80.29%
Description
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
Affected products
No data.
Configuration 1
- < 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4
- 11.4r13
- 11.4x27
- 12.1
- 12.1r
- 12.1x44
- 12.1x44
- 12.1x44
- 12.1x44
- 12.1x44
- 12.1x44
- 12.1x44
- 12.1x45
- 12.1x45
- 12.1x45
- 12.1x45
- 12.1x46
- 12.1x46
- 12.1x46
- 12.1x47
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 13.1
- 13.1
- 13.1
- 13.1
- 13.2
- 13.2
- 13.2
- 13.2
- 13.3
- 13.3
Configuration 2
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 5
- ≤ 8.6
- 9.2.0
- 9.2.1
- 9.2.2
Configuration 6
Configuration 7
- 5.0.6
- 5.0.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The DHS advisory is a good source of background information about the issue: https://www.cisa.gov/news-events/alerts/2004/04/20/vulnerabilities-tcp It is important to note that the issue described is a known function of TCP. In order to perform a connection reset an attacker would need to know the source and destination ip address and ports as well as being able to guess the sequence number within the window. These requirements seriously reduce the ability to trigger a connection reset on normal TCP connections. The DHS advisory explains that BGP routing is a specific case where being able to trigger a reset is easier than expected as the end points can be easily determined and large window sizes are used. BGP routing is also signficantly affected by having its connections terminated. The major BGP peers have recently switched to requiring md5 signatures which mitigates against this attack. The following article from Linux Weekly News also puts the flaw into context and shows why it does not pose a significant threat: https://lwn.net/Articles/81560/ Red Hat does not have any plans for action regarding this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 80.29% (0.80286) | 99.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 80.86% (0.80855) | 99.58th | v5 (v2026.06.15) |
| Jun 11, 2026 | 10.73% (0.10735) | 93.50th | v4 (v2025.03.14) |
| Dec 28, 2025 | 9.61% (0.09613) | 92.61th | v4 (v2025.03.14) |
| Dec 27, 2025 | 11.48% (0.11484) | 93.41th | v4 (v2025.03.14) |
| Oct 28, 2025 | 9.61% (0.09613) | 92.51th | v4 (v2025.03.14) |
| Oct 27, 2025 | 11.48% (0.11484) | 93.32th | v4 (v2025.03.14) |
| Oct 1, 2025 | 8.88% (0.08885) | 92.27th | v4 (v2025.03.14) |
| May 11, 2025 | 11.76% (0.11758) | 93.29th | v4 (v2025.03.14) |
| May 6, 2025 | 13.07% (0.13071) | 93.68th | v4 (v2025.03.14) |
| May 3, 2025 | 10.09% (0.10093) | 92.70th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.13% (0.08125) | 91.36th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.99% (0.01991) | 72.78th | v4 (v2025.03.14) |
| Mar 28, 2025 | 8.13% (0.08125) | 91.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.10% (0.04098) | 87.83th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.95% (0.01950) | 88.38th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.27% (0.00265) | 65.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00265) | 62.34th | v3 (v2023.03.01) |
| Mar 6, 2023 | 17.79% (0.17792) | 96.26th | v2 (v2022.01.01) |
| Apr 1, 2022 | 17.79% (0.17792) | 95.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 17.79% (0.17792) | 93.35th | v2 (v2022.01.01) |
No CWE recorded.
References (32)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc vendor-advisoryx_refsource_NETBSDBroken LinkThird Party Advisory
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt vendor-advisoryx_refsource_SCOBroken LinkThird Party Advisory
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt vendor-advisoryx_refsource_SCOBroken LinkThird Party Advisory
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt vendor-advisoryx_refsource_SCOBroken LinkThird Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc vendor-advisoryx_refsource_SGIBroken LinkThird Party Advisory
- http://kb.juniper.net/JSA10638 x_refsource_CONFIRMThird Party Advisory
- http://marc.info/?l=bugtraq&m=108302060014745&w=2 mailing-listx_refsource_BUGTRAQMailing List
- http://marc.info/?l=bugtraq&m=108506952116653&w=2 vendor-advisoryx_refsource_HPMailing List
- http://secunia.com/advisories/11440 third-party-advisoryx_refsource_SECUNIABroken LinkPermissions RequiredThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/11458 third-party-advisoryx_refsource_SECUNIABroken LinkPermissions RequiredThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/22341 third-party-advisoryx_refsource_SECUNIABroken LinkPermissions RequiredThird Party AdvisoryVDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml vendor-advisoryx_refsource_CISCOBroken Link
- http://www.kb.cert.org/vuls/id/415294 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.osvdb.org/4030 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/archive/1/449179/100/0/threaded vendor-advisoryx_refsource_HPBroken Link
- http://www.securityfocus.com/bid/10183 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- http://www.uniras.gov.uk/vuls/2004/236929/index.htm x_refsource_MISCBroken Link
- http://www.us-cert.gov/cas/techalerts/TA04-111A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2006/3983 vdb-entryx_refsource_VUPENBroken LinkPermissions Required
- https://access.redhat.com/security/cve/CVE-2004-0230 Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019 vendor-advisoryx_refsource_MSThird Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-064 vendor-advisoryx_refsource_MSThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15886 vdb-entryx_refsource_XFThird Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10053 x_refsource_CONFIRMBroken LinkPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0230
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2689 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A270 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3508 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4791 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5711 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2004-0230
Change history (0)
No recorded changes yet.