CVE-2024-0209

HIGH

Wireshark 3.6.0-3.6.19, 4.0.0-4.0.11, 4.2.0 - Denial of Service in IEEE 1609.2 Dissector

Title source: llm
STIX 2.1

Description

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

References (3)

Core 3
Core References
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://gitlab.com/wireshark/wireshark/-/issues/19501

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-476
Status published
Products (5)
wireshark/wireshark 4.2.0
wireshark/wireshark 3.6.0 - 3.6.19
Wireshark Foundation/Wireshark 3.6.0 - 3.6.20
Wireshark Foundation/Wireshark 4.0.0 - 4.0.12
Wireshark Foundation/Wireshark 4.2.0 - 4.2.1
Published Jan 03, 2024
Tracked Since Feb 18, 2026