<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>CVE-2004-0230 Blind Reset Attack Using the RST/SYN Bit</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-16-039</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2020-05-20T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2020-05-20T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2020-05-20T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            TCP stacks that lack RFC 5961 3.2 &amp; 4.2 support (or have it disabled at application level) may allow remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST or SYN packet.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Denial of service
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiAnalyzer version 5.2.0 through 5.2.9FortiAnalyzer version 6.0.0 through 6.0.11FortiAnalyzer version 6.2.0 through 6.2.3FortiAuthenticator version 5.5.0FortiAuthenticator version 6.0.0 through 6.0.5FortiAuthenticator version 6.2.0 through 6.2.1FortiManager version 5.2.0 through 5.2.9FortiManager version 6.0.0 through 6.0.11FortiManager version 6.2.0 through 6.2.3FortiOS version 5.2.0 through 5.2.8FortiOS version 5.4.0 through 5.4.1FortiWAN version 4.5.0 through 4.5.4FortiWLC version 8.4.0 through 8.4.8FortiWLC version 8.5.0 through 8.5.5FortiWLC version 8.6.0
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            Upgrade to FortiAnalyzer version 6.2.4 or aboveUpgrade to FortiAnalyzer version 6.4.0 or aboveUpgrade to FortiAuthenticator version 6.3.0 or aboveUpgrade to FortiAuthenticator version 6.0.6 or aboveUpgrade to FortiManager version 6.2.4 or aboveUpgrade to FortiManager version 6.4.0 or aboveUpgrade to FortiOS version 5.6.0 or aboveUpgrade to FortiOS version 5.4.2 or aboveUpgrade to FortiOS version 5.2.9 or aboveUpgrade to FortiWAN version 4.5.5 or aboveUpgrade to FortiWLC version 8.6.1 or aboveWorkaround:Restrict hosts that can connect to the GUI to trusted ones only, with the trusted host feature.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-16-039</cvrf:URL>
            <cvrf:Description>CVE-2004-0230 Blind Reset Attack Using the RST/SYN Bit</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>The following issues reported by vulnerability scanners are directly linked to this issue: &#34;TCP Sequence Number Approximation Based Denial of Service&#34; &#34;Blind Reset Attack Using the RST/SYN Bit&#34;</cvrf:URL>
            <cvrf:Description>The following issues reported by vulnerability scanners are directly linked to this issue: &#34;TCP Sequence Number Approximation Based Denial of Service&#34; &#34;Blind Reset Attack Using the RST/SYN Bit&#34;</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <Vulnerability Ordinal="1">
        <Title>CVE-2004-0230 Blind Reset Attack Using the RST/SYN Bit</Title>
        <cvrf:CVE>CVE-2004-0230</cvrf:CVE>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.3</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-16-039</URL>
                <Description>CVE-2004-0230 Blind Reset Attack Using the RST/SYN Bit</Description>
            </Reference>Reference>
            <Reference>
                <URL>The following issues reported by vulnerability scanners are directly linked to this issue: &#34;TCP Sequence Number Approximation Based Denial of Service&#34; &#34;Blind Reset Attack Using the RST/SYN Bit&#34;</URL>
                <Description>The following issues reported by vulnerability scanners are directly linked to this issue: &#34;TCP Sequence Number Approximation Based Denial of Service&#34; &#34;Blind Reset Attack Using the RST/SYN Bit&#34;</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>