PT-2025-49838 · Tcp · Tcp

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-40820

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Affected products (affected versions not specified)
Description The software does not properly validate TCP sequence numbers in certain situations, accepting a wide range of values. This could allow a remote attacker to disrupt connection establishment, potentially causing a denial of service. Successful exploitation requires the attacker to inject IP packets with spoofed addresses at precise times, and the issue only impacts services using TCP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-00196
CVE-2025-40820

Affected Products

Tcp