Hijacking TCP Sessions Could Lead to Denial of Service in H3C Routers
CVE-2023-30311

7.5HIGH

Key Information:

Vendor
H3C
Vendor
CVE Published:
28 May 2024

Summary

A vulnerability identified in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions due to improper handling of sequence number leakage. This flaw can be exploited to disrupt normal service, leading to potential denial of service. Attackers may take advantage of this vulnerability to intercept and manipulate traffic, posing significant risks to network integrity and stability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.