In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Feb 20, 2019 | Jun 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 19, 2017 |
| Suse | — | Upgrade libwireshark8Upgrade libsmiUpgrade portaudio-develUpgrade portaudioUpgrade wireshark-develUpgrade libwiretap6Upgrade libwsutil7Upgrade libwscodecs1Upgrade wiresharkUpgrade wireshark-gtkUpgrade libwiretap7Upgrade libwsutil8Upgrade libwireshark9 | Sep 25, 2017 | Jun 21, 2017 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Jun 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub