National Cyber-Alert System
Vulnerability Summary for CVE-2005-3774
Original release date:11/23/2005
Last revised:09/05/2008
Source:
US-CERT/NIST
Overview
Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including (1) SYN packets with invalid checksums, which do not result in a RST; or, from an external interface, (2) one byte of "meaningless data," or (3) a TTL that is one less than needed to reach the internal destination.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
2.9
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Allows disruption of serviceUnknown
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Vulnerability Note: VU#853540
Name: VU#853540
External Source: XF
Name: cisco-pix-ttl-dos(25079)
External Source: XF
Name: cisco-pix-tcp-data-field-dos(25077)
External Source: BID
Name: 15525
External Source: BUGTRAQ
Name: 20060307 RE: Cisco PIX embryonic state machine 1b data DoS
External Source: BUGTRAQ
Name: 20060307 Cisco PIX embryonic state machine TTL(n-1) DoS
External Source: BUGTRAQ
Name: 20060307 Cisco PIX embryonic state machine 1b data DoS
External Source: BUGTRAQ
Name: 20051122 Cisco PIX TCP Connection Prevention
External Source: OSVDB
Name: 24140
External Source: VUPEN
Name: ADV-2005-2546
External Source: CISCO
Name: 20051128 Response to Cisco PIX TCP Connection Prevention
External Source: CONFIRM
Name: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a0080624a37.html
External Source: SECTRACK
Name: 1015256
External Source: SECUNIA
Name: 17670
External Source: FULLDISC
Name: 20051122 Cisco PIX TCP Connection Prevention
External Source: FULLDISC
Name: 20051122 Cisco PIX TCP Connection Prevention
Type: Advisory