CVE detail
CVE-2020-35685 — CVE-2020-35685
Published 2021-08-19 · Modified 2026-06-17 · Vendor hcc-embedded · Product nichestack · Source nvd
CRITICAL
severity
CVSS-derived band
0.0205
EPSS probability
exploitation probability, 30d
79.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.)
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References