CVE-2022-3724

MEDIUM

Wireshark < 3.6.8 - Format String Vulnerability

Title source: rule
STIX 2.1

Description

Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows

Scores

CVSS v3 6.3
EPSS 0.0038
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-134
Status published
Products (1)
wireshark/wireshark 3.6.0 - 3.6.8
Published Dec 09, 2022
Tracked Since Feb 18, 2026