CVE-2001-0323
Last modified
CVE-2001-0323 is a vulnerability of currently unknown severity. The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0323?
How severe is CVE-2001-0323?
How do I fix CVE-2001-0323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0317Race condition in ptrace in Linux kernel 2.4 and 2.2 allows …
- CVE-2001-0318Format string vulnerability in ProFTPD 1.2.0rc2 may allow at…
- CVE-2001-0319orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote at…
- CVE-2001-0320bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows rem…
- CVE-2001-0321opendir.php script in PHP-Nuke allows remote attackers to re…
- CVE-2001-0322MSHTML.DLL HTML parser in Internet Explorer 4.0, and other v…
- CVE-2001-0324Windows 98 and Windows 2000 Java clients allow remote attack…
- CVE-2001-0325Buffer overflow in QNX RTP 5.60 allows remote attackers to c…
- CVE-2001-0326Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Orac…
- CVE-2001-0327iPlanet Web Server Enterprise Edition 4.1 and earlier allows…
- CVE-2001-0328TCP implementations that use random increments for initial s…
- CVE-2001-0329Bugzilla 2.10 allows remote attackers to execute arbitrary c…
Are you affected by CVE-2001-0323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
