CVE-2021-39923 Vulnerability Details
/
/
/
CVE-2021-39923 Metadata Quick Info
CVE Published: 19/11/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021
Source: GitLab |
Vendor: Wireshark Foundation |
Product: Wireshark
Status : PUBLISHED
CVE-2021-39923 Description
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* NONE
Integrity Impact (I)* NONE
Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: Excessive iteration in Wireshark
Source: Wireshark Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).