CVE-2009-1210
Wireshark < 1.0.6 - Remote Code Execution via PN-DCP Station Name Format String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1210. PoCs published by THCX Labs.
AI-analyzed exploit summary This exploit leverages a format string vulnerability in Wireshark <= 1.0.6 by crafting a malicious PN-DCP packet. The PoC generates a pcap file containing the exploit payload and uses tcpreplay to send it, potentially causing a crash or arbitrary code execution.
Description
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit leverages a format string vulnerability in Wireshark <= 1.0.6 by crafting a malicious PN-DCP packet. The PoC generates a pcap file containing the exploit payload and uses tcpreplay to send it, potentially causing a crash or arbitrary code execution.