Attackers Can Hijack TCP Sessions in Openwrt Routers, Leading to Denial of Service
CVE-2023-30312

7.3HIGH

Key Information:

Vendor

Openwrt

Vendor
CVE Published:
28 May 2024

What is CVE-2023-30312?

An identified vulnerability in OpenWrt allows off-path attackers to hijack TCP sessions due to the default setting of nf_conntrack_tcp_no_window_check. This weakness can result in unauthorized access and manipulation of client-server communications, enabling attackers to impersonate either side. Consequently, attackers could deliver misleading information or gain unwarranted access to sensitive files, posing significant security risks to users and their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.