Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-3188


The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.


Published

2012-05-24T23:55:02.213

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 3.1 Yes
Operating System redhat enterprise_linux 4.0 Yes
Application f5 arx ≤ 6.4.0 Yes
Application f5 big-ip_access_policy_manager ≤ 10.2.4 Yes
Application f5 big-ip_access_policy_manager ≤ 11.1.0 Yes
Application f5 big-ip_analytics ≤ 11.1.0 Yes
Application f5 big-ip_application_security_manager ≤ 10.2.4 Yes
Application f5 big-ip_application_security_manager ≤ 11.1.0 Yes
Application f5 big-ip_edge_gateway ≤ 10.2.4 Yes
Application f5 big-ip_edge_gateway ≤ 11.1.0 Yes
Application f5 big-ip_global_traffic_manager ≤ 10.2.4 Yes
Application f5 big-ip_global_traffic_manager ≤ 11.1.0 Yes
Application f5 big-ip_link_controller ≤ 10.2.4 Yes
Application f5 big-ip_link_controller ≤ 11.1.0 Yes
Application f5 big-ip_local_traffic_manager ≤ 10.2.4 Yes
Application f5 big-ip_local_traffic_manager ≤ 11.1.0 Yes
Application f5 big-ip_protocol_security_module ≤ 10.2.4 Yes
Application f5 big-ip_protocol_security_module ≤ 11.1.0 Yes
Application f5 big-ip_wan_optimization_manager ≤ 10.2.4 Yes
Application f5 big-ip_wan_optimization_manager ≤ 11.1.0 Yes
Application f5 big-ip_webaccelerator ≤ 10.2.4 Yes
Application f5 big-ip_webaccelerator ≤ 11.1.0 Yes
Application f5 enterprise_manager ≤ 2.3.0 Yes
Application f5 enterprise_manager 3.0.0 Yes
Application f5 firepass ≤ 6.1.0 Yes
Application f5 firepass 7.0.0 Yes

References