MEDIUM
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced
Published Jan 19, 2005
5.0
MEDIUMCVSS 2.0
EPSS 54.39%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.