Impact
The vulnerability is an uninitialized variable in the ESS protocol dissector of Wireshark. When the dissector processes certain ESS packets, the uninitialized data can cause a crash. An attacker who delivers a crafted ESS packet—typically by delivering a malicious capture file—can trigger the crash, resulting in a denial‑of‑service condition for the user running Wireshark.
Affected Systems
Wireshark Foundation Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The likely attack vector is a crafted ESS packet processed by a local Wireshark instance, which requires the attacker to convince a user to open a malicious capture file or otherwise have Wireshark dissect the traffic. Although remote exploitation is possible in that sense, it depends on user interaction, lowering the overall exploitation probability. Nevertheless, any crash of Wireshark interrupts security monitoring and could impact critical workflows.
OpenCVE Enrichment
Debian DSA