← Vulnerability feed

Vulnerability record · CVE-2005-0356 · published 31 May 2005

CVE-2005-0356: TCP PAWS timestamp handling allows remote connection loss

Cisco · Agent Desktop

Multiple TCP implementations that enable the timestamps option with Protection Against Wrapped Sequence Numbers (PAWS) can be forced to discard valid packets. A spoofed packet carrying a large timestamp value makes later legitimate packets appear too old, causing connection loss. Because the flaw spans many TCP stacks, it affects a broad set of network devices and operating systems.

5.0 CVSS 2.0 Medium EPSS 83% · top 0.3%
5.0CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
76Affected product versions listed by NVD
22References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated denial of service with a very high EPSS score and public exploit references, though impact is limited to availability.

What it is

Multiple TCP implementations that enable the timestamps option with Protection Against Wrapped Sequence Numbers (PAWS) can be forced to discard valid packets. A spoofed packet carrying a large timestamp value makes later legitimate packets appear too old, causing connection loss. Because the flaw spans many TCP stacks, it affects a broad set of network devices and operating systems.

Impact

An attacker can cause denial of service by breaking established TCP connections, disrupting services that rely on long-lived sessions. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker only needs to deliver a spoofed TCP packet with a manipulated timestamp to a host using PAWS.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.82756, 99.65th percentile) and a reference is tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.

What to do

  • Apply vendor patches for affected TCP stacks; a patch-tagged advisory is referenced.
  • Disable TCP timestamps where operationally feasible to remove the PAWS dependency.
  • Filter or rate-limit spoofed TCP traffic at network boundaries and enable ingress/egress anti-spoofing.
  • Monitor vendor advisories for the full list of affected products and versions, since the record does not enumerate them.

Detection

  • Monitor for abrupt, unexplained TCP session resets or connection drops across many hosts.
  • Inspect TCP timestamp values in traffic for anomalies such as unexpectedly large or non-monotonic timestamps.
  • Correlate connection-loss events with spoofed-packet indicators or unusual source addresses at the network edge.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

76 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0356 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1760Cisco emergency responder improper authentication vulnerabilityThe default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authenticat…EPSS 3.8%9.3CVE-2007-4634Cisco unified communications manager sql injection vulnerabilityMultiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 be…EPSS 4.3%7.8CVE-2012-1350Cisco ios vulnerabilityCisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3…EPSS 1.9%7.8CVE-2009-2976Cisco aironet ap1100 vulnerabilityCisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to…EPSS 1.4%7.8CVE-2006-0368Cisco call manager vulnerabilityCisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denia…EPSS 3.7%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.3CVE-2009-2861Cisco aironet ap1100 vulnerabilityThe Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access…EPSS 1.0%6.5CVE-2006-0367Cisco call manager vulnerabilityUnspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2005-0356), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.