CVE-2004-0230

Juniper Junos - Denial of Service via TCP RST Packet Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2004-0230. PoCs published by K-sPecial, Paul A. Watson, Aphex.

AI-analyzed exploit summary This Perl script exploits CVE-2004-0230 by sending crafted TCP RST packets with approximated sequence numbers to reset established TCP sessions. It iterates through a range of sequence numbers and ports to increase the likelihood of a successful reset.

Description

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Exploits (7)

exploitdb WORKING POC VERIFIED
by K-sPecial · perlremotemultiple
https://www.exploit-db.com/exploits/24033

This Perl script exploits CVE-2004-0230 by sending crafted TCP RST packets with approximated sequence numbers to reset established TCP sessions. It iterates through a range of sequence numbers and ports to increase the likelihood of a successful reset.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Racy
Target: Multiple TCP implementations (e.g., BGP, Microsoft platforms)
No auth needed
Prerequisites: Knowledge of source/destination IP addresses and ports · Long-lived TCP connections
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Paul A. Watson · cdoslinux
https://www.exploit-db.com/exploits/291

This exploit code crafts and sends TCP RST packets to disrupt established TCP connections by guessing sequence numbers. It uses libnet to construct raw Ethernet, IP, and TCP packets with spoofed source/destination MAC and IP addresses.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Racy
Target: TCP/IP stack (generic, affects systems processing TCP packets)
No auth needed
Prerequisites: Network access to target · Ability to send raw packets (root/admin privileges) · Knowledge of target IP, port, and MAC address
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Aphex · doswindows
https://www.exploit-db.com/exploits/276

This Delphi program crafts and sends TCP RST packets to forcibly terminate established TCP connections. It allows customization of source/destination IP/port, window size, and sequence numbers to disrupt targeted connections.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: TCP/IP stack (generic)
No auth needed
Prerequisites: Network access to target · Knowledge of active TCP connection parameters
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Paul Watson · textremotemultiple
https://www.exploit-db.com/exploits/24032

The document describes a TCP sequence number approximation vulnerability (CVE-2004-0230) that allows remote attackers to reset TCP sessions by injecting SYN or RST packets with forged source IP/port and approximated sequence numbers. It highlights the impact on long-lived connections like BGP and mentions ongoing investigations into affected vendors.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: Multiple TCP implementations (vendor-specific details not provided)
No auth needed
Prerequisites: knowledge of target IP/port · ability to approximate TCP sequence numbers
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Paul A. Watson · perlremotemultiple
https://www.exploit-db.com/exploits/24031

This Perl script exploits CVE-2004-0230 by sending a flood of TCP RST packets to disrupt BGP connections. It leverages predictable sequence numbers and source ports to forge packets, targeting long-lived TCP sessions.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: TCP implementations (e.g., BGP on Cisco routers, Microsoft platforms)
No auth needed
Prerequisites: knowledge of target IP, source port, and sequence number · Net::RawIP module
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Matt Edman · cremotemultiple
https://www.exploit-db.com/exploits/24030

This exploit demonstrates a TCP session reset vulnerability (CVE-2004-0230) by sniffing network traffic and forging RST packets to terminate active TCP connections. It leverages WinPCAP to capture packets and craft malicious RST packets with approximated sequence numbers.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple TCP implementations (e.g., BGP, Microsoft platforms)
No auth needed
Prerequisites: Network access to sniff traffic · WinPCAP installed · Non-switched network environment
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
cdoswindows
https://www.exploit-db.com/exploits/942

This exploit demonstrates a DoS vulnerability in Windows by crafting a malformed IP packet with an option size of 39, causing an off-by-one error. The PoC uses libnet to construct and send the packet, triggering a crash in the target system.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (various versions, likely pre-2005)
No auth needed
Prerequisites: Network access to the target · Ability to send raw IP packets
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (29)

Core 29
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-111A.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108302060014745&w=2
Broken Link vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/449179/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-064
Broken Link, Permissions Required, Third Party Advisory, VDB Entry third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11440
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/JSA10638
Broken Link, Patch, Third Party Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10053
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/415294
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=108506952116653&w=2
Broken Link, Third Party Advisory vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt
Broken Link, Third Party Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc
Third Party Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019
Broken Link vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml
Broken Link, Third Party Advisory vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt
Exploit, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10183
Broken Link, Third Party Advisory vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt
Third Party Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15886
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/4030
Broken Link, Permissions Required, Third Party Advisory, VDB Entry third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22341
Broken Link, Third Party Advisory vendor-advisory x_refsource_netbsd
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc
Broken Link, Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3983
Broken Link, Permissions Required, Third Party Advisory, VDB Entry third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11458

Scores

EPSS 0.1074
EPSS Percentile 93.5%

Details

Status published
Products (13)
juniper/junos 11.4 (11 CPE variants)
juniper/junos 11.4r13 s2
juniper/junos 11.4x27
juniper/junos 12.1
juniper/junos 12.1r
juniper/junos 12.1x44 (7 CPE variants)
juniper/junos 12.1x45 (4 CPE variants)
juniper/junos 12.1x46 (3 CPE variants)
juniper/junos 12.1x47
juniper/junos 12.2 (8 CPE variants)
... and 3 more
Published Aug 18, 2004
Tracked Since Feb 18, 2026