CVE-2004-0230
Summary
| CVE | CVE-2004-0230 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-08-18 04:00:00 UTC |
| Updated | 2026-10-09 20:17:02 UTC |
| Description | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Juniper | Junos | All | All | All | All |
| Operating System | Juniper | Junos | 11.4 | - | All | All |
| Operating System | Juniper | Junos | 11.4 | r1 | All | All |
| Operating System | Juniper | Junos | 11.4 | r10 | All | All |
| Operating System | Juniper | Junos | 11.4 | r2 | All | All |
| Operating System | Juniper | Junos | 11.4 | r3 | All | All |
| Operating System | Juniper | Junos | 11.4 | r4 | All | All |
| Operating System | Juniper | Junos | 11.4 | r5 | All | All |
| Operating System | Juniper | Junos | 11.4 | r6 | All | All |
| Operating System | Juniper | Junos | 11.4 | r7 | All | All |
| Operating System | Juniper | Junos | 11.4 | r8 | All | All |
| Operating System | Juniper | Junos | 11.4 | r9 | All | All |
| Operating System | Juniper | Junos | 11.4r13 | s2 | All | All |
| Operating System | Juniper | Junos | 11.4x27 | All | All | All |
| Operating System | Juniper | Junos | 12.1 | - | All | All |
| Operating System | Juniper | Junos | 12.1r | All | All | All |
| Operating System | Juniper | Junos | 12.1x44 | - | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d10 | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d15 | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d20 | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d25 | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d30 | All | All |
| Operating System | Juniper | Junos | 12.1x44 | d35 | All | All |
| Operating System | Juniper | Junos | 12.1x45 | - | All | All |
| Operating System | Juniper | Junos | 12.1x45 | d10 | All | All |
| Operating System | Juniper | Junos | 12.1x45 | d15 | All | All |
| Operating System | Juniper | Junos | 12.1x45 | d20 | All | All |
| Operating System | Juniper | Junos | 12.1x46 | - | All | All |
| Operating System | Juniper | Junos | 12.1x46 | d10 | All | All |
| Operating System | Juniper | Junos | 12.1x46 | d15 | All | All |
| Operating System | Juniper | Junos | 12.1x47 | - | All | All |
| Operating System | Juniper | Junos | 12.2 | - | All | All |
| Operating System | Juniper | Junos | 12.2 | r1 | All | All |
| Operating System | Juniper | Junos | 12.2 | r2 | All | All |
| Operating System | Juniper | Junos | 12.2 | r3 | All | All |
| Operating System | Juniper | Junos | 12.2 | r4 | All | All |
| Operating System | Juniper | Junos | 12.2 | r5 | All | All |
| Operating System | Juniper | Junos | 12.2 | r6 | All | All |
| Operating System | Juniper | Junos | 12.2 | r7 | All | All |
| Operating System | Juniper | Junos | 12.3 | - | All | All |
| Operating System | Juniper | Junos | 12.3 | r1 | All | All |
| Operating System | Juniper | Junos | 12.3 | r2 | All | All |
| Operating System | Juniper | Junos | 12.3 | r3 | All | All |
| Operating System | Juniper | Junos | 12.3 | r4 | All | All |
| Operating System | Juniper | Junos | 12.3 | r5 | All | All |
| Operating System | Juniper | Junos | 13.1 | - | All | All |
| Operating System | Juniper | Junos | 13.1 | r1 | All | All |
| Operating System | Juniper | Junos | 13.1 | r2 | All | All |
| Operating System | Juniper | Junos | 13.1 | r3 | All | All |
| Operating System | Juniper | Junos | 13.2 | - | All | All |
| Operating System | Juniper | Junos | 13.2 | r1 | All | All |
| Operating System | Juniper | Junos | 13.2 | r2 | All | All |
| Operating System | Juniper | Junos | 13.2 | r3 | All | All |
| Operating System | Juniper | Junos | 13.3 | - | All | All |
| Operating System | Juniper | Junos | 13.3 | r1 | All | All |
| Application | Mcafee | Network Data Loss Prevention | 9.2.0 | All | All | All |
| Application | Mcafee | Network Data Loss Prevention | 9.2.1 | All | All | All |
| Application | Mcafee | Network Data Loss Prevention | 9.2.2 | All | All | All |
| Application | Mcafee | Network Data Loss Prevention | All | All | All | All |
| Operating System | Microsoft | Windows 2000 | - | sp3 | All | All |
| Operating System | Microsoft | Windows 2000 | - | sp4 | All | All |
| Operating System | Microsoft | Windows 98 | - | All | All | All |
| Operating System | Microsoft | Windows 98se | - | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | - | All | x64 | All |
| Operating System | Microsoft | Windows Xp | - | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | All | All |
| Operating System | Netbsd | Netbsd | 1.5 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.5.1 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.5.2 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.5.3 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.6 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.6.1 | All | All | All |
| Operating System | Netbsd | Netbsd | 1.6.2 | All | All | All |
| Operating System | Netbsd | Netbsd | 2.0 | All | All | All |
| Application | Openpgp | Openpgp | 2.6.2 | All | All | All |
| Operating System | Oracle | Solaris | 10 | All | All | All |
| Operating System | Oracle | Solaris | 11 | All | All | All |
| Operating System | Xinuos | Openserver | 5.0.6 | All | All | All |
| Operating System | Xinuos | Openserver | 5.0.7 | All | All | All |
| Operating System | Xinuos | Unixware | 7.1.1 | All | All | All |
| Operating System | Xinuos | Unixware | 7.1.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | Broken Link, Third Party Advisory |
| Microsoft Windows Multiple IPv6 Denial of Service Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Permissions Required, Third Party Advisory, VDB Entry |
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | Broken Link, Third Party Advisory |
| US-CERT Vulnerability Note VU#415294 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Secunia - Advisories - Juniper Networks Products TCP Connection Reset Denial of Service | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Permissions Required, Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory |
| Microsoft Security Bulletin MS06-064 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| Microsoft Security Bulletin MS05-019 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | Third Party Advisory |
| '[security bulletin] SSRT4696 rev. 0 HP ProCurve Routing Switches TCP Denial of Service (DoS)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| McAfee KnowledgeBase - McAfee Security Bulletin – Network Data Loss Prevention addresses 17 security issues | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Broken Link, Patch, Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| www.osvdb.org/4030 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| 'Perl code exploting TCP not checking RST ACK.' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| Multiple Vendor TCP Sequence Number Approximation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Third Party Advisory, VDB Entry |
| patches.sgi.com/support/free/security/advisories/20040403-01-A.asc | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | Broken Link, Third Party Advisory |
| Juniper Networks - 2014-07 Security Bulletin: Junos: Denial of Service in TCP packet processing (CVE-2004-0230) | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | Third Party Advisory |
| Secunia - Advisories - Cisco IOS TCP Connection Reset Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Permissions Required, Third Party Advisory, VDB Entry |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Permissions Required |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | Broken Link, Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA04-111A -- Vulnerabilities in TCP | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Oracle Critical Patch Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | Broken Link, Third Party Advisory |
| www.uniras.gov.uk/vuls/2004/236929/index.htm | af854a3a-2127-422b-91ae-364da2661108 | www.uniras.gov.uk | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-08-16 | Mark J Cox | The DHS advisory is a good source of background information about the issue: http://www.us-cert.gov/cas/techalerts/TA04-111A.html It is important to note that the issue described is a known function of TCP. In order to perform a connection reset an attacker would need to know the source and destination ip address and ports as well as being able to guess the sequence number within the window. These requirements seriously reduce the ability to trigger a connection reset on normal TCP connections. The DHS advisory explains that BGP routing is a specific case where being able to trigger a reset is easier than expected as the end points can be easily determined and large window sizes are used. BGP routing is also signficantly affected by having it’s connections terminated. The major BGP peers have recently switched to requiring md5 signatures which mitigates against this attack. The following article from Linux Weekly News also puts the flaw into context and shows why it does not pose a significant threat: http://lwn.net/Articles/81560/ Red Hat does not have any plans for action regarding this issue. |
There are currently no legacy QID mappings associated with this CVE.