I wouldn't say that it's a false positive... It's still a vulnerability in the TCP stack that the vendor provides, but it is mitigated by the factor that all of the communications are encrypted.
+------------------------------------------ | Jos� J. Cintr�n - <[EMAIL PROTECTED]> +------------------------------------------ -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bilal Nasrallah Sent: Wednesday, June 15, 2005 16:10 To: [email protected] Subject: Predictable TCP sequence number Folks, I ran a scan against a network device and one of the vulnerability highlighted by the report was "Predictable TCP sequence number". I reported this issue to the vendor. However, the vender replied back that indicating that shouldn't be an issue because all TCP sessions to the device are encrypted via SSL or SSH and require password authentication. Would the vulnerability in this case considered a false positive? Thanks, Bilal _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
