CVE-2011-3188
criticalCVSS v3 Base Score
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
4.3%
Exploitation probability in 30 days
Top 11% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
High
Availability
High
Vulnerability Report
Generated by CyberWatcher
Description
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
CWE
NVD-CWE-OtherAffected Products
linux linux kernelredhat enterprise linuxf5 arxf5 big-ip access policy managerf5 big-ip analyticsf5 big-ip application security managerf5 big-ip edge gatewayf5 big-ip global traffic managerf5 big-ip link controllerf5 big-ip local traffic manager