CVE detail
CVE-2005-4440 — CVE-2005-4440
Published 2005-12-21 · Modified 2026-06-16 · Vendor vlan_protocol · Product vlan_protocol · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0161
EPSS probability
exploitation probability, 30d
74.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The 802.1q VLAN protocol allows remote attackers to bypass network segmentation and spoof VLAN traffic via a message with two 802.1q tags, which causes the second tag to be redirected from a downstream switch after the first tag has been stripped, as demonstrated by Yersinia, aka "double-tagging VLAN jumping attack."
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References