Heap-Based Buffer Over-Read in Tcpreplay by AppNeta
CVE-2022-27941

7.8HIGH

Key Information:

Vendor
Broadcom
Status
Vendor
CVE Published:
26 March 2022

Summary

Tcpreplay version 4.4.1 contains a heap-based buffer over-read vulnerability identified in the get_l2len_protocol function within the common/get.c file. This flaw can potentially be exploited by an attacker, leading to unintended data exposure or denial of service. Users of affected versions should review their configurations and apply necessary updates to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.