CVE-2005-3774
Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create...
- Published
- Nov 23, 2005
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Nov 22, 2005
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:PModerate · next 30 days
- Percentile
- 97.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including (1) SYN packets with invalid checksums, which do not result in a RST; or, from an external interface, (2) one byte of "meaningless data," or (3) a TTL that is one less than needed to reach the internal destination.
Sources
2Janis Vizulis · hardware · Nov 23, 2005
Janis Vizulis · hardware · Nov 22, 2005
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.