CVE-2016-5696

Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 06 Aug 2016, 20:00
Last modified:06 Aug 2024, 01:08

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
5.8 MEDIUM
v2.0 (nvd)
EPSS Score
51.99% CRITICAL
52% probability +17.58%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Aug 2016, 20:00
Published
Vulnerability first disclosed
06 Aug 2024, 01:08
Last Modified
Vulnerability information updated

Description

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS Metrics

  • v3.0MEDIUMScore: 4.8CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 51.99% Percentile: 98%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • googleandroid

    ≤ 7.0

  • linuxlinux_kernel

    ≤ 4.6.6

  • oraclevm_server

    3.3 | 3.4

References (32)