In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Feb 20, 2019 | Jun 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 19, 2017 |
| Suse | — | Upgrade libwiretap6Upgrade wiresharkUpgrade wireshark-develUpgrade libsmiUpgrade libwireshark8Upgrade portaudioUpgrade libwscodecs1Upgrade portaudio-develUpgrade libwsutil7Upgrade libwiretap7Upgrade wireshark-gtkUpgrade libwireshark9Upgrade libwsutil8 | Sep 25, 2017 | Jun 21, 2017 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Jun 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub