Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections.
https://exchange.xforce.ibmcloud.com/vulnerabilities/139
http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html