Predictable TCP Initial Sequence Numbers (ISNs) in GE Digital Energy Hydran M2 Ethernet Card

Predictable TCP Initial Sequence Numbers (ISNs) in GE Digital Energy Hydran M2 Ethernet Card

CVE-2014-5409 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.

Learn more about our Web Application Penetration Testing UK.