Vulnerabilities > CVE-2023-2906 - Divide By Zero vulnerability in Wireshark

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
wireshark
CWE-369

Summary

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

Vulnerable Configurations

Part Description Count
Application
Wireshark
148

Common Weakness Enumeration (CWE)