CVE-2004-1060
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 74.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 74.67% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- icmp/icmp · tcp/tcp
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt
- http://marc.info/?l=bugtraq&m=112861397904255&w=2
- http://secunia.com/advisories/18317
- http://securityreason.com/securityalert/19
- http://securityreason.com/securityalert/57
- http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtmlVendor Advisory
- http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/418882/100/0/threaded
- http://www.securityfocus.com/bid/13124
- http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=enVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A196
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2188
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3826
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A405
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5386
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A651
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A780
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A899
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt
- http://marc.info/?l=bugtraq&m=112861397904255&w=2
- http://secunia.com/advisories/18317
- http://securityreason.com/securityalert/19
- http://securityreason.com/securityalert/57
- http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtmlVendor Advisory
- http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/418882/100/0/threaded
- http://www.securityfocus.com/bid/13124
- http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=enVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.