CVE-2005-0066 describes a design flaw in TCP where ICMP error messages from intermediate routers do not properly validate the TCP Acknowledgment number. This vulnerability allows attackers to forge ICMP messages, leading to denial-of-service attacks such as blind connection resets, throughput reduction via source quench, or Path MTU reduction. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it represents a moderate-severity issue that can be exploited over the network with low complexity and no authentication, primarily impacting availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:tcp:tcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.