Forum Discussion
dw_888_212625
Nimbostratus
Nov 17, 2015removal/disable of tcp timestamp with reference to CVE-2005-0356
removal/disable of tcp timestamp with reference to CVE-2005-0356,
please advise is it recommended to remove tcp timestamp on f5 or on the server side to mitigate this vulnerability?
dw_888_212625
Nimbostratus
Nov 18, 2015There seem to be a contradicting statement between the CVE-2005-0356 description and F5’s statement: · the CVE-2005-0356 description in https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-0356 states that PAWS used with timestamp option enabled is vulnerable to DoS · in contrast, https://support.f5.com/kb/en-us/solutions/public/8000/000/sol8072.html PAWS can protect against DoS attacks
kindly advise
- Brad_ParkerNov 18, 2015
Cirrus
I suggest you open a support case.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects