5
CVSSv2

CVE-2016-10728

Published: 23/07/2018 Updated: 20/09/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Suricata prior to 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suricata-ids suricata

Github Repositories

IDS Bypass tricks

Disclaimer These programs is for Educational purpose ONLY Do not use it without permission inject_server: Proof-Of-Concept for CVE-2018-6794 If as a server side you break a normal TCP 3 way handshake packets order and inject some response data before 3whs is complete then data still will be received by the client but some IDS engines may skip content checks on that Client