CVE-2005-0065 describes a fundamental design flaw in TCP where ICMP error messages are not properly validated against active TCP connections. This vulnerability affects all implementations of TCP and allows attackers to forge ICMP messages to disrupt network traffic. With a CVSS score of 10.0, it presents a critical risk, enabling denial-of-service attacks through blind connection resets, throughput reduction, or Path MTU manipulation. While no public exploit intelligence or active exploitation is reported, the underlying design flaw makes it a significant theoretical concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:tcp:tcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.