Sceawere
Vulnerability Detail
CVE-2026-95390UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PEAK CAN TRC Parser DoS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-476: NULL Pointer Dereference
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:15.160Z",
"pubdate": "2026-09-29T10:17:15.160Z",
"executiveSummary": "A denial-of-service (DoS) vulnerability exists within the PEAK CAN TRC file parser, specifically impacting versions 4.6.0 through 4.6.8.\nThe vulnerability originates from improper handling of malformed or maliciously crafted TRC data files, leading to an application crash.\nThe primary impact is the loss of availability for the PEAK CAN software suite when processing untrusted input files.\nThis flaw allows an attacker to terminate the application process by supplying a specially crafted file, potentially interrupting diagnostic or logging activities.\nThe vulnerability does not require authentication for exploitation, though it necessitates that the victim process a file provided or controlled by the attacker.\nThe risk is categorized as a service disruption, where the application's stability is compromised upon parsing input that violates expected file format specifications.",
"technicalDetails": "The vulnerability resides in the internal logic responsible for parsing the PEAK CAN TRC file format. The TRC format is a log file standard used for CAN bus data acquisition. Versions 4.6.0 to 4.6.8 contain a flaw in the parser that fails to perform adequate bounds checking or input validation when processing specific file structures or headers.\nWhen the PEAK CAN software attempts to ingest a TRC file, the parser iterates through the data stream to map the contents into internal memory structures. If the file contains malformed metadata, unexpected byte sequences, or structural inconsistencies, the parser fails to handle these edge cases gracefully. This results in an unhandled exception or memory access violation, forcing the application to terminate unexpectedly.\nThe attack flow involves an adversary creating a malicious TRC file designed to trigger the identified parser error. The attacker then delivers this file to the target system—potentially through email attachments, compromised file shares, or direct transfer to a user who then loads the file into the PEAK CAN software. Once the application begins parsing the corrupted file, the specific trigger condition causes the process to crash.\nBecause the crash occurs during the parsing stage, the vulnerability can be leveraged without the attacker having established a prior session or possessing specific privileges on the host system. The requirement is limited to the interaction between the software and the file-handling component. If the software is configured to auto-import or continuously monitor directories for log files, this could potentially be exploited in an automated fashion if the attacker can drop files into the monitored location.\nThe post-exploitation impact is strictly a denial-of-service. The application terminates, preventing further logging, monitoring, or analysis operations until the user manually restarts the software. There is no evidence currently suggesting that this crash can be leveraged for arbitrary code execution, though it fundamentally breaks the intended functional lifecycle of the affected parser component in the defined version range."
}