CVE-2026-3202

Plain English Summary

AI-powered analysis for quick understanding

An attacker can cause Wireshark to crash, leading to a denial of service, by sending specially crafted packets that exploit a flaw in how the software processes the NTS-KE protocol. This vulnerability affects versions 4.6.0 to 4.6.3, so users running these versions are at risk.

Technical Description

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References