CVE-2004-1799
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2004
Last modified:
03/04/2025
Description
PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:openbsd:openbsd:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:3.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



