Impact
An integer coercion error in the ippReadChunkedBody function of bettercap’s zerogod IPP Service can cause unsafe integer conversions that may lead to application failure or service disruption. The vulnerability can be accessed remotely and requires complex input manipulation. Exploitation remains difficult.
Affected Systems
All installations of bettercap up to and including version 2.41.5 are affected. The flaw resides in the zerogod IPP Service module and applies to any deployed instance that processes IPP requests.
Risk and Exploitability
With a CVSS score of 6.3 the flaw presents a moderate risk; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers must remotely deliver a specially crafted IPP request containing malformed data that triggers the integer coercion error. The high complexity and difficult exploitation reduce the likelihood of widespread attacks at this time.
OpenCVE Enrichment