Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2018-6922 | First vendor Publication | 2018-08-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | |||
---|---|---|---|
Overall CVSS Score | 5.3 | ||
Base Score | 5.3 | Environmental Score | 5.3 |
impact SubScore | 1.4 | Temporal Score | 5.3 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | None |
Integrity Impact | None | Availability Impact | Low |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6922 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09618.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09619.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09620.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09621.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09622.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09623.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09624.nasl - Type : ACT_GATHER_INFO |
2018-11-09 | Name : The remote AIX host is missing a security patch. File : aix_IJ09625.nasl - Type : ACT_GATHER_INFO |
2018-08-07 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_3c2eea8c99bf11e88beea4badb2f4699.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 13:22:36 |
|
2021-05-04 13:19:03 |
|
2021-04-22 02:35:27 |
|
2020-05-23 01:19:00 |
|
2019-10-10 05:20:46 |
|
2019-10-03 09:21:26 |
|
2019-03-20 17:18:59 |
|
2019-01-17 00:19:30 |
|
2018-10-11 17:19:48 |
|
2018-08-16 17:19:28 |
|
2018-08-14 17:19:42 |
|
2018-08-11 09:19:15 |
|
2018-08-10 00:19:30 |
|