CVE-2004-0790

TCP/IP ICMP Error Handling - Blind Connection Reset Denial of Service

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2004-0790. PoCs published by houseofdabus, Fernando Gont.

AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2004-0790, demonstrating ICMP-based attacks against TCP connections. It allows an attacker to send crafted ICMP messages to reset TCP connections, slow down traffic, or consume system resources.

Description

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

Exploits (3)

exploitdb WORKING POC VERIFIED
by houseofdabus · cdosmultiple
https://www.exploit-db.com/exploits/948

This is a proof-of-concept exploit for CVE-2004-0790, demonstrating ICMP-based attacks against TCP connections. It allows an attacker to send crafted ICMP messages to reset TCP connections, slow down traffic, or consume system resources.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple Cisco and Microsoft products (e.g., Cisco IOS, Windows Server 2003, Windows XP)
No auth needed
Prerequisites: Network access to the target system · Ability to spoof ICMP packets
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Fernando Gont · textdosmultiple
https://www.exploit-db.com/exploits/25389

This is a writeup describing multiple ICMP-based denial-of-service vulnerabilities (CVE-2004-0790, CVE-2004-0791, CVE-2004-1060) affecting various TCP/IP implementations. It explains blind connection-reset, ICMP Source Quench, and PMTUD attacks but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: Multiple vendor TCP/IP implementations (including Microsoft)
No auth needed
Prerequisites: Network access to target · Ability to forge ICMP packets
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
cdoswindows
https://www.exploit-db.com/exploits/942

This exploit demonstrates a DoS vulnerability in Windows by crafting a malformed IP packet with an option size of 39, causing a crash due to an off-by-one error in IP option processing.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (unspecified version)
No auth needed
Prerequisites: Network access to target · Ability to send raw IP packets
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (27)

Core 27
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A412
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4804
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13124
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/418882/100/0/threaded
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/449179/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A176
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A514
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1910
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=112861397904255&w=2
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1
Various Sources vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1177
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18317
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3458
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A211
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/19
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/57
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22341
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3983
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A53
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A622

Scores

EPSS 0.8513
EPSS Percentile 99.4%

Details

Status published
Products (10)
microsoft/windows_2000 (2 CPE variants)
microsoft/windows_2003_server r2
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
microsoft/windows_xp (4 CPE variants)
sun/solaris 9.0
sun/solaris 10.0
sun/sunos 5.7
sun/sunos 5.8
Published Apr 12, 2005
Tracked Since Feb 18, 2026