CVE Vulnerabilities

CVE-2014-9196

Predictable Exact Value from Previous Values

Published: Jul 20, 2015 | Modified: Sep 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

Weakness

An exact value or random number can be precisely predicted by observing previous values.

Affected Software

NameVendorStart VersionEnd Version
ProviewEaton4.0 (including)4.0 (including)
ProviewEaton5.0 (including)5.0 (including)
ProviewEaton5.0.1 (including)5.0.1 (including)
ProviewEaton5.0.2 (including)5.0.2 (including)
ProviewEaton5.0.3 (including)5.0.3 (including)
ProviewEaton5.0.4 (including)5.0.4 (including)
ProviewEaton5.0.5 (including)5.0.5 (including)
ProviewEaton5.0.6 (including)5.0.6 (including)
ProviewEaton5.0.7 (including)5.0.7 (including)
ProviewEaton5.0.8 (including)5.0.8 (including)
ProviewEaton5.0.9 (including)5.0.9 (including)
ProviewEaton5.0.10 (including)5.0.10 (including)

Potential Mitigations

References