Description
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-3994 | Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value. |
References
History
No history.
Subscriptions
Schneider-electric
Subscribe
Sage 1210
Subscribe
Sage 1230
Subscribe
Sage 1250
Subscribe
Sage 1310
Subscribe
Sage 1330
Subscribe
Sage 1350
Subscribe
Sage 1410
Subscribe
Sage 1430
Subscribe
Sage 1450
Subscribe
Sage 2200
Subscribe
Sage 2400
Subscribe
Sage 3030
Subscribe
Sage 3030 Magnum
Subscribe
Windriver
Subscribe
Vxworks
Subscribe
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-06T06:04:01.028Z
Reserved: 2015-05-12T00:00:00.000Z
Link: CVE-2015-3963
No data.
Status : Deferred
Published: 2015-08-04T01:59:07.357
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-3963
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD