Detailedlikelihood: Mediumseverity: LowStable
CAPEC-326TCP Initial Window Size Probe
Abstraction
Detailed
Status
Stable
Likelihood
Medium
Severity
Low
Description
This OS fingerprinting probe checks the initial TCP Window size. TCP stacks limit the range of sequence numbers allowable within a session to maintain the "connected" state within TCP protocol logic. The initial window size specifies a range of acceptable sequence numbers that will qualify as a response to an ACK packet within a session. Various operating systems use different Initial window sizes. The initial window size can be sampled by establishing an ordinary TCP connection.
Related weaknesses· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.