Vulnerability Name: | CVE-2005-3945 (CCN-23284) | ||||||||
Assigned: | 2005-11-28 | ||||||||
Published: | 2005-11-28 | ||||||||
Updated: | 2019-04-30 | ||||||||
Summary: | The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Nov 28 2005 - 15:53:45 CST Flaw in Syn Attack Protection on non-updated Microsoft OSes can lead to DoS Source: MITRE Type: CNA CVE-2005-3945 Source: CCN Type: Microsoft.com Web site Download details: Microsoft Windows Server 2003 SP1 Source: CCN Type: OSVDB ID: 21510 Microsoft Windows SynAttackProtect Bypass Source: BUGTRAQ Type: UNKNOWN 20051128 Flaw in Syn Attack Protection on non-updated Microsoft OSes can lead to DoS Source: BID Type: UNKNOWN 15613 Source: CCN Type: BID-15613 Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability Source: XF Type: UNKNOWN win-synattackprotect-dos(23284) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |