Lucene search

K
kasperskyKaspersky LabKLA70415
HistoryMay 15, 2024 - 12:00 a.m.

KLA70415 DoS vulnerability in Wireshark

2024-05-1500:00:00
Kaspersky Lab
threats.kaspersky.com
7
wireshark
dos
vulnerability
update
cve-2024-4855

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

16.3%

Denial of Service vulnerability was found in Wireshark. Malicious users can exploit this vulnerability to cause denial of service.

Original advisories

wnpa-sec-2024-09 · Editcap secret injection crash

Related products

Wireshark

CVE list

CVE-2024-4855 warning

Solution

Update to the latest version

Download Wireshark

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • Wireshark 4.2.x earlier than 4.2.5Wireshark 4.0.x earlier than 4.0.15Wireshark 3.6.x earlier than 3.6.24

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

16.3%