
🚨 HIGH: CVE-2025-40820 (CVSS 7.5) TCP sequence validation flaw allows unauthenticated remote DoS via spoofed packets. Affects TCP-based services. Requires precise timing but no authentication. #CVE #Vulnerability #PatchNow https://t.co/3n21fdgqjC
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote attacker e.g. to interfere with connection setup, potentially leading to a denial of service. The attack succeeds only if an attacker can inject IP packets with spoofed addresses at precisely timed moments, and it affects only TCP-based services.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🚨 HIGH: CVE-2025-40820 (CVSS 7.5) TCP sequence validation flaw allows unauthenticated remote DoS via spoofed packets. Affects TCP-based services. Requires precise timing but no authentication. #CVE #Vulnerability #PatchNow https://t.co/3n21fdgqjC