PT-2024-28734 · Tcp · Tcp
Daniel Gruss
+1
·
Published
2024-07-03
·
Updated
2024-08-05
·
CVE-2024-39920
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TCP protocol (affected versions not specified)
Description
The issue is related to a timing side channel in the TCP protocol, making it easier for remote attackers to infer the content of one TCP connection from a client system to any server. This can occur when the client system is concurrently obtaining TCP data at a slow rate from an attacker-controlled server. The attack can begin by measuring RTTs via the TCP segments whose role is to provide an ACK control bit and an Acknowledgment Number.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tcp