Secunia Logo
Netsikker nu! 2008
 
Cisco IOS TCP Connection Reset Denial of Service Vulnerability
Secunia Advisory: SA11440
Release Date: 2004-04-21
Popularity: 17,126 views

Critical:
Less critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Cisco IOS 11.x
Cisco IOS 12.x
Cisco IOS R11.x
Cisco IOS R12.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2004-0230


Description:
Paul A. Watson has published research about a somewhat known vulnerability in the TCP specification (RFC793), which can be exploited by malicious people to cause a DoS (Denial of Service). Cisco has acknowledged that Cisco IOS is affected.

According to the TCP specification, an established TCP connection can be reset by sending a suitable TCP packet with the RST or SYN flag set. Since a source IP address and port can be forged, this may potentially be exploited by a malicious person to reset a connection between other systems.

However, in the past, this has only been thought of as a theoretical security issue, as a valid 32-bit sequence number is required for the so-called "spoofing attack" to be successful, and the probability of guessing a correct sequence number is extremely low.

It has now been proven that exploitation is possible. The problem is that the probability of guessing an acceptable sequence number is much higher than expected, since the receiving TCP implementation accepts any sequence number in a certain range ("window") of the correct sequence number.

This can be exploited to reset an established TCP connection on a vulnerable device by sending a specially crafted TCP packet with an acceptable sequence number and a forged source IP address and port.

Especially long-lived TCP connections with a guessable source port and protocols like BGP and DNS (for zone transfers) are affected.

NOTE: See the original advisory for a list of affected versions.

Solution:
See patch matrix in original advisory.

Provided and/or discovered by:
Paul A. Watson

Original Advisory:
http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml

Other References:
NISCC:
http://www.uniras.gov.uk/vuls/2004/236929/index.htm

US-CERT Technical Cyber Security Alert TA04-111A:
http://www.us-cert.gov/cas/techalerts/TA04-111A.html

US-CERT VU#415294:
http://www.kb.cert.org/vuls/id/415294

OSVDB:
http://www.osvdb.org/4030

RFC793 - Transmission Control Protocol:
http://www.ietf.org/rfc/rfc0793.txt

RFC1323 - TCP Extensions for High Performance:
http://www.ietf.org/rfc/rfc1323.txt


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 199 views
Debian update for php5
Moderately // 145 views
Atarone CMS Multiple Vulnerabilities
Moderately // 183 views
Debian update for squid
Less // 195 views
SUSE update for mercurial
Moderately // 242 views
SUSE update for openssh
Less // 186 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Debian update for php5 // 57 views
2. SUSE update for openssh // 48 views
3. WMNews Cross-Site Scripting Vulnerabilities // 46 views
4. H-Sphere webshell4 Cross-Site Scripting and Request Forgery // 45 views
5. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 41 views
6. SUSE update for mercurial // 32 views
7. Fedora update for mediawiki // 31 views
8. HP-UX NFS/ONCplus Denial of Service Vulnerability // 30 views
9. CMME Information Disclosure Security Issues // 30 views
10. Atarone CMS Multiple Vulnerabilities // 30 views