Vulnerability record · CVE-2005-0068 · published 22 December 2004
CVE-2005-0068: ICMP lacks authentication, enabling forged error message TCP denial of service
Tcp · Tcp
The original ICMP design does not authenticate host-generated error messages, so attackers can forge them against specific TCP connections. This allows blind connection-reset attacks via forged Destination Unreachable messages and throughput-reduction attacks via forged Source Quench or Path MTU messages. It matters because any TCP session can be disrupted without seeing the traffic.
Description
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityCVSS 2.0 is 5.0 (MEDIUM) with availability-only impact, and while EPSS is high, there is no KEV listing or confirmed exploit evidence in the record.
What it is
The original ICMP design does not authenticate host-generated error messages, so attackers can forge them against specific TCP connections. This allows blind connection-reset attacks via forged Destination Unreachable messages and throughput-reduction attacks via forged Source Quench or Path MTU messages. It matters because any TCP session can be disrupted without seeing the traffic.
Impact
An attacker can blindly reset established TCP connections or reduce their throughput, causing denial of service. No data confidentiality or integrity is gained; the effect is availability loss.
Attack surface
Reachable over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker only needs to send forged ICMP messages toward a target connection.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.54387, 98.96th percentile), but the references are advisory and a SecurityFocus BID with no exploit tags, so active exploitation is not confirmed by this record.
What to do
- Apply vendor patches or configuration guidance that hardens TCP against forged ICMP error messages.
- Filter or rate-limit inbound ICMP error messages at network boundaries where operationally feasible.
- Disable processing of unnecessary ICMP types such as Source Quench and redirects on hosts and routers.
- Enable TCP hardening options that ignore ICMP hard errors for established connections where supported.
- Monitor for repeated connection resets or throughput drops correlated with ICMP error traffic.
Detection
- Alert on spikes of inbound ICMP Destination Unreachable, Source Quench, or fragmentation-needed messages tied to established TCP flows.
- Correlate sudden TCP connection resets or throughput drops with concurrent ICMP error traffic from unexpected sources.
- Baseline normal ICMP error volume per host and flag deviations, especially from external or spoofed-looking addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0068 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0068), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.