Search:     Advanced search
server monitoring

Cisco IOS TCP Sequence Prediction Connection Hijacking (CSCds04747)

Article ID: 10976
Last updated: 27 Jan, 2009
Views: 442
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Cisco IOS TCP Sequence Prediction Connection Hijacking (CSCds04747)

This script is (C) 2002-2009 Tenable Network Security, Inc.

FamilyCISCO
Plugin ID10976
Bugtraq ID2682
CVE IDCVE-2001-0288
CVE-2001-0328

Description:


Cisco IOS Software contains a flaw that permits the successful
prediction of TCP Initial Sequence Numbers.

This vulnerability is present in all released versions of Cisco IOS
software running on Cisco routers and switches. It only affects the
security of TCP connections that originate or terminate on the
affected Cisco device itself
it does not apply to TCP traffic
forwarded through the affected device in transit between two other
hosts.


This vulnerability is documented as Cisco bug ID CSCds04747.

Solution :
http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml
Risk factor : Medium

*** As solely relied on the banner of the remote host
*** this might be a false positive
This article was:   Helpful | Not Helpful
Prev   Next
Cisco VPN 3000 Series Multiple Vulnerabilities (CSCdea77143,...     Cisco IOS Malformed BGP Packet Processing Remote DoS (CSCee67450)