Impact
A heap‑based buffer overflow exists in the Wireshark Foundation ciscodump utility for versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The flaw is triggered during normal packet‑capture parsing, causing the program to crash and resulting in a denial‑of‑service condition. The vulnerability is catalogued as CWE‑122 (Unchecked Bounds Check) and involves a potential null‑pointer dereference identified as CWE‑476.
Affected Systems
Any installation of ciscodump within the affected series—Wireshark Foundation ciscodump 4.6.x from 4.6.0 to 4.6.6 and 4.4.x from 4.4.0 to 4.4.16—is susceptible. Users who run ciscodump to analyze packet captures, particularly in unattended or automated environments, are at risk if their system hosts one of these releases.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of <1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation. The likely attack vector is local, inferred from the requirement that the attacker supplies or induces the analysis of a crafted packet capture; remote exploitation is not supported by the available data.
OpenCVE Enrichment