Description
Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Published: 2026-07-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the Wireshark Foundation ciscodump utility for versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The flaw is triggered during normal packet‑capture parsing, causing the program to crash and resulting in a denial‑of‑service condition. The vulnerability is catalogued as CWE‑122 (Unchecked Bounds Check) and involves a potential null‑pointer dereference identified as CWE‑476.

Affected Systems

Any installation of ciscodump within the affected series—Wireshark Foundation ciscodump 4.6.x from 4.6.0 to 4.6.6 and 4.4.x from 4.4.0 to 4.4.16—is susceptible. Users who run ciscodump to analyze packet captures, particularly in unattended or automated environments, are at risk if their system hosts one of these releases.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, and the EPSS score of <1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation. The likely attack vector is local, inferred from the requirement that the attacker supplies or induces the analysis of a crafted packet capture; remote exploitation is not supported by the available data.

Generated by OpenCVE AI on July 29, 2026 at 13:21 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.7 or above


OpenCVE Recommended Actions

  • Upgrade ciscodump to version 4.6.7 or later
  • Restrict execution of ciscodump to trusted users and prevent processing of untrusted packet capture files while remediation is pending
  • Monitor logs for unexpected ciscodump crashes to detect potential exploitation attempts

Generated by OpenCVE AI on July 29, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark ciscodump
Vendors & Products Wireshark
Wireshark ciscodump

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Title Heap-based Buffer Overflow in ciscodump
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Ciscodump
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T13:50:08.985Z

Reserved: 2026-07-08T20:45:18.867Z

Link: CVE-2026-15164

cve-icon Vulnrichment

Updated: 2026-07-09T13:50:00.582Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T20:50:35Z

Links: CVE-2026-15164 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:30:06Z

Weaknesses