Description
Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Published: 2026-08-13
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow occurs while parsing Ixia IxVeriWave and Vector Informatik BLF files in Wireshark versions 4.6.0 through 4.6.7. The flaw leads to an out‑of‑bounds write (CWE-787) that can crash the application and cause a denial of service on Windows systems when a malicious file is processed. The crash is limited to the Wireshark process and does not directly provide arbitrary code execution or remote influence, but it can disrupt network monitoring services.

Affected Systems

The vulnerability affects Wireshark Foundation’s Wireshark product, specifically releases 4.6.0 to 4.6.7. Updated versions 4.6.8 and later contain the fix.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity. There is no EPSS score available and the vulnerability is not listed in CISA’s KEV catalog, suggesting the exploitation landscape is limited or not yet observed. Attackers are likely to trigger the flaw by providing a crafted BLF file to a Windows installation of Wireshark, which may be feasible if the user opens an untrusted capture file. Because the issue does not provide remote code execution, the risk is confined to local denial of service.

Generated by OpenCVE AI on August 13, 2026 at 09:28 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or newer.
  • Avoid opening unknown or untrusted BLF files, especially from unverified sources.
  • Run Wireshark in a controlled or sandboxed environment to contain any potential crash.
  • Check with the vendor for any additional advisories or firmware updates.

Generated by OpenCVE AI on August 13, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Thu, 13 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Title Out-of-bounds Write in Wireshark
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-13T08:04:29.277Z

Reserved: 2026-08-13T07:35:09.042Z

Link: CVE-2026-19696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T09:17:12.983

Modified: 2026-08-13T09:17:12.983

Link: CVE-2026-19696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:30:07Z

Weaknesses