Description
An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the client to the server (e.g., for access to files over FTP), and impersonating the server to the client (e.g., to deliver false information from a finance website). This occurs because nf_conntrack_tcp_no_window_check is true by default.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 07 Nov 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-203 | |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-07T11:15:57.558Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-30312
Updated: 2024-08-02T14:21:44.933Z
Status : Deferred
Published: 2024-05-28T22:15:11.247
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-30312
No data.
OpenCVE Enrichment
No data.
Weaknesses