Is the Edge SWG (ProxySG) or ISG Proxy Vulnerable to CVE-2004-0230?
search cancel

Is the Edge SWG (ProxySG) or ISG Proxy Vulnerable to CVE-2004-0230?

book

Article ID: 166639

calendar_today

Updated On:

Products

ProxySG Software - SGOS ISG Proxy

Issue/Introduction

You want to know if the Edge SWG (ProxySG) or ISG Proxy appliances are vulnerable to CVE-2004-0230, "TCP Sequence Number Approximation Based Denial of Service".

Resolution

The Edge SWG/ISG Proxy appliance is hardened against this sort of attack. The appliance compares the incoming sequence number to the last ACK we sent and the next sequence number we expect to receive.  If it is not equal to or is within 1 in either direction, we drop the packet.