Vulnerability record · CVE-2005-0356 · published 31 May 2005
CVE-2005-0356: TCP PAWS timestamp handling allows remote connection loss
Cisco · Agent Desktop
Multiple TCP implementations that enable the timestamps option with Protection Against Wrapped Sequence Numbers (PAWS) can be forced to discard valid packets. A spoofed packet carrying a large timestamp value makes later legitimate packets appear too old, causing connection loss. Because the flaw spans many TCP stacks, it affects a broad set of network devices and operating systems.
Description
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated denial of service with a very high EPSS score and public exploit references, though impact is limited to availability.
What it is
Multiple TCP implementations that enable the timestamps option with Protection Against Wrapped Sequence Numbers (PAWS) can be forced to discard valid packets. A spoofed packet carrying a large timestamp value makes later legitimate packets appear too old, causing connection loss. Because the flaw spans many TCP stacks, it affects a broad set of network devices and operating systems.
Impact
An attacker can cause denial of service by breaking established TCP connections, disrupting services that rely on long-lived sessions. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker only needs to deliver a spoofed TCP packet with a manipulated timestamp to a host using PAWS.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.82756, 99.65th percentile) and a reference is tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Apply vendor patches for affected TCP stacks; a patch-tagged advisory is referenced.
- Disable TCP timestamps where operationally feasible to remove the PAWS dependency.
- Filter or rate-limit spoofed TCP traffic at network boundaries and enable ingress/egress anti-spoofing.
- Monitor vendor advisories for the full list of affected products and versions, since the record does not enumerate them.
Detection
- Monitor for abrupt, unexplained TCP session resets or connection drops across many hosts.
- Inspect TCP timestamp values in traffic for anomalies such as unexpectedly large or non-monotonic timestamps.
- Correlate connection-loss events with spoofed-packet indicators or unusual source addresses at the network edge.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
76 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0356 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0356), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.