Vulnerability Details CVE-2014-7250
The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2014-7250
-
-
cpe:2.3:o:freebsd:freebsd:5.4
-
cpe:2.3:o:netbsd:netbsd:2.0
-
cpe:2.3:o:openbsd:openbsd:3.6