High-Severity Vulnerabilities Discovered in ... : vimarsana.

High-Severity Vulnerabilities Discovered in ...


The vulnerabilities—the same across all nine stacks—involve the manner in which the so-called Initial Sequence Number (ISN) is generated.
The ISN ensures that every TCP connection is unique, that there are no collisions with other connections, and that no third party can interfere with an ongoing connection. To guarantee this, the ISN is randomly generated so no one can guess the number and use it to hijack an ongoing connection or spoof a new one.
Forescout's analysis showed problems with the manner in which the TCP/IP stacks that were analyzed generate the ISNs. In nine of the 11 stacks, the ISNs were improperly generated, leaving the connections open to attacks. In some cases, the numbers were predictable, and in others, the problem had to do with the underlying algorithm. In other cases, the numbers had constant increments, while others used a combination of values that could be inferred, Forescout said in its report.

Related Keywords

, Research Labs , High Severity Vulnerabilities Discovered , Multiple Embedded , Transmission Control Protocol , Initial Sequence Number , Texas Instrument , Siemen Nucleus , Dos Santos , Project Memoria , Senior Editor , View Full , ஆராய்ச்சி ஆய்வகங்கள் , பல பதிக்கப்பட்ட , பரவும் முறை கட்டுப்பாடு ப்ரோடொகால் , ஆரம்ப வரிசை எண் , டெக்சாஸ் கருவி , டோஸ் சாண்டோஸ் , ப்ராஜெக்ட் நினைவகம் , மூத்தவர் ஆசிரியர் , பார்வை முழு ,

© 2025 Vimarsana