← Vulnerability feed

Vulnerability record · CVE-2005-0068 · published 22 December 2004

CVE-2005-0068: ICMP lacks authentication, enabling forged error message TCP denial of service

Tcp · Tcp

The original ICMP design does not authenticate host-generated error messages, so attackers can forge them against specific TCP connections. This allows blind connection-reset attacks via forged Destination Unreachable messages and throughput-reduction attacks via forged Source Quench or Path MTU messages. It matters because any TCP session can be disrupted without seeing the traffic.

5.0 CVSS 2.0 Medium EPSS 54% · top 1.0%
5.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 5.0 (MEDIUM) with availability-only impact, and while EPSS is high, there is no KEV listing or confirmed exploit evidence in the record.

What it is

The original ICMP design does not authenticate host-generated error messages, so attackers can forge them against specific TCP connections. This allows blind connection-reset attacks via forged Destination Unreachable messages and throughput-reduction attacks via forged Source Quench or Path MTU messages. It matters because any TCP session can be disrupted without seeing the traffic.

Impact

An attacker can blindly reset established TCP connections or reduce their throughput, causing denial of service. No data confidentiality or integrity is gained; the effect is availability loss.

Attack surface

Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker only needs to send forged ICMP messages toward a target connection.

Exploitation

Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.54387, 98.96th percentile), but the references are advisory and a SecurityFocus BID with no exploit tags, so active exploitation is not confirmed by this record.

What to do

  • Apply vendor patches or configuration guidance that hardens TCP against forged ICMP error messages.
  • Filter or rate-limit inbound ICMP error messages at network boundaries where operationally feasible.
  • Disable processing of unnecessary ICMP types such as Source Quench and redirects on hosts and routers.
  • Enable TCP hardening options that ignore ICMP hard errors for established connections where supported.
  • Monitor for repeated connection resets or throughput drops correlated with ICMP error traffic.

Detection

  • Alert on spikes of inbound ICMP Destination Unreachable, Source Quench, or fragmentation-needed messages tied to established TCP flows.
  • Correlate sudden TCP connection resets or throughput drops with concurrent ICMP error traffic from unexpected sources.
  • Baseline normal ICMP error volume per host and flag deviations, especially from external or spoofed-looking addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0068 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-0068), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.