Vulnerability record · CVE-2004-1060 · published 12 April 2004
CVE-2004-1060: TCP/IP Path MTU Discovery DoS via Forged ICMP Packets
Icmp · Icmp
Multiple TCP/IP and ICMP implementations mishandle Path MTU Discovery (PMTUD), allowing a remote attacker to send forged ICMP "Fragmentation Needed and Don't Fragment was Set" messages carrying a low next-hop MTU. The victim host then shrinks its path MTU and reduces TCP throughput, degrading or stalling connections. The record does not enumerate specific affected products or versions.
Description
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated availability impact with high EPSS but no KEV listing and only partial product detail, warranting patching and ICMP filtering rather than emergency response.
What it is
Multiple TCP/IP and ICMP implementations mishandle Path MTU Discovery (PMTUD), allowing a remote attacker to send forged ICMP "Fragmentation Needed and Don't Fragment was Set" messages carrying a low next-hop MTU. The victim host then shrinks its path MTU and reduces TCP throughput, degrading or stalling connections. The record does not enumerate specific affected products or versions.
Impact
An attacker can cause a denial of service by forcing persistent network throughput reduction on TCP connections. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable remotely over the network by sending crafted ICMP packets to a host that uses PMTUD; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high at 0.7467 (99.5th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply vendor patches for affected TCP/IP stacks (e.g., Microsoft MS05-019, Cisco advisory, SCO updates) as the first action.
- Disable or restrict Path MTU Discovery where it is not required, or configure the stack to ignore untrusted ICMP Fragmentation Needed messages.
- Filter inbound ICMP unreachable/Fragmentation Needed packets at network boundaries so forged messages cannot reach internal hosts.
- Validate ICMP error messages against expected next-hop MTU ranges and drop those advertising implausibly low MTUs.
- Monitor for repeated MTU changes or throughput drops on long-lived TCP sessions and rate-limit ICMP error traffic.
Detection
- Alert on spikes of inbound ICMP type 3 code 4 (Fragmentation Needed and DF set) packets, especially with unusually low MTU values.
- Correlate ICMP error bursts with simultaneous TCP throughput degradation or retransmission increases on affected hosts.
- Log and review PMTU cache changes on routers and hosts for values below expected link MTUs.
- Use IDS/IPS signatures for forged ICMP Fragmentation Needed packets targeting PMTUD.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1060 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1060), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.