CVE-2024-9780
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Oct 10, 2024
Updated: Oct 17, 2024
CWE ID 456
CWE ID 909
Summary
CVE-2024-9780 refers to a denial-of-service vulnerability affecting Wireshark 4.4.0. The ITS (Internet Telephony Signaling) dissector in this version is susceptible to crashing due to packet injection or specially crafted capture files. Successful exploitation of this issue results in Wireshark becoming unresponsive, thereby impeding network analysis and monitoring tasks. This vulnerability could potentially be leveraged by an attacker to disrupt network operations, affecting productivity and security investigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wireshark
Affected Vendors
- Wireshark Foundation