PT-2024-28734 · Tcp · Tcp

Daniel Gruss

+1

·

Published

2024-07-03

·

Updated

2024-08-05

·

CVE-2024-39920

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TCP protocol (affected versions not specified)
Description The issue is related to a timing side channel in the TCP protocol, making it easier for remote attackers to infer the content of one TCP connection from a client system to any server. This can occur when the client system is concurrently obtaining TCP data at a slow rate from an attacker-controlled server. The attack can begin by measuring RTTs via the TCP segments whose role is to provide an ACK control bit and an Acknowledgment Number.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-39920

Affected Products

Tcp