Impact
The vulnerability is a null pointer dereference in the NTS-KE protocol dissector of Wireshark. When a malformed NTS‑KE packet is parsed, the program crashes, causing a denial of service. The flaw is categorized as CWE‑476, indicating unsafe use of a null pointer.
Affected Systems
Wireshark Foundation’s Wireshark product, versions 4.6.0 through 4.6.3, are affected. The vulnerability is specific to the NTS‑KE dissector in these releases.
Risk and Exploitability
The CVSS score is 4.7, indicating a medium severity. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the receipt of crafted NTS‑KE network traffic; an attacker could embed a rogue packet in a network stream to trigger the crash if the target is actively dissecting traffic.
OpenCVE Enrichment