An issue was discovered in Suricata 5.0.0. It was possible...
Vulnerability Description
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP Timestamp option. The client will ignore the RST ACK and the FIN ACK packets because of the bad TCP Timestamp option. Both linux and windows client are ignoring the injected packets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18625
Credits & Attribution
No credits recorded in the NVD database.
References
- https://redmine.openinfosecfoundation.org/issues/3286
- https://github.com/OISF/suricata/commit/9f0294fadca3dcc18c919424242a41e01f3e8318
- https://redmine.openinfosecfoundation.org/issues/3395
- https://github.com/OISF/suricata/commit/ea0659de7640cf6a51de5bbd1dbbb0414e4623a0
- https://lists.debian.org/debian-lts-announce/2020/01/msg00032.html
More from oisf
View All →Affected Vendor
oisf
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.