Impact
Sonic 3 A.I.R. has a missing source‑address validation flaw in its ConnectionManager module. An attacker who can observe clear‑text UDP traffic can craft packets that contain any two‑byte connection identifier, thereby injecting arbitrary packets into existing sessions. The attacker can terminate a session with a TerminateConnectionPacket, forge channel messages, and fabricate request responses, all without IP spoofing. This results in loss of integrity of the connection, potential denial of service, and unauthorized control of the session.
Affected Systems
The vulnerability affects the Sonic 3 A.I.R. product from the vendor Eukaryot. All releases before the code change identified by commit 2492d18 are vulnerable. No specific version numbers are listed, but any build predating that commit should be considered at risk.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An on‑path attacker who can eavesdrop on clear‑text UDP traffic can exploit the flaw by forging the two‑byte connection handle; no IP spoofing is required. The attack requires network access to the compromised link and the ability to send UDP packets to the vulnerable instance.
OpenCVE Enrichment