SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0790

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have…

MEDIUM 5.0EPSS 80.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 80.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
80.10% probability · 100th percentile
CISA KEV
Not listed
Affected
microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows me · microsoft/windows xp · sun/solaris · sun/sunos
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.