Sceawere
Vulnerability Detail
CVE-2026-95392UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MBIM Protocol Dissector Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-126: Buffer Over-read
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:15.457Z",
"pubdate": "2026-09-29T10:17:15.457Z",
"executiveSummary": "This vulnerability involves a memory management error or state handling flaw within the MBIM (Mobile Broadband Interface Model) protocol dissector. The vulnerability manifests as a crash, leading to a Denial of Service (DoS) condition when the dissector processes malformed or specifically crafted MBIM traffic.\nAffected versions include 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. The flaw is primarily localized to the protocol parsing engine, where improper validation of input fields triggers an unhandled exception or illegal memory access.\nThe risk implication is high for environments relying on network traffic analysis or deep packet inspection (DPI) of cellular data protocols, as an attacker can remotely trigger the failure without requiring prior authentication. Successful exploitation terminates the dissector process, rendering the affected system unable to analyze traffic, potentially bypassing security monitoring or disrupting management interfaces depending on the product architecture.\nExploitation requires the attacker to transmit a crafted MBIM frame to the target interface where the dissector is active. No special privileges are required for the attacker beyond network access to the target receiving the MBIM traffic.",
"technicalDetails": "The vulnerability resides within the MBIM protocol dissector, a component responsible for parsing and reconstructing Mobile Broadband Interface Model data frames. The root cause is attributed to an improper handling of protocol-specific fields, likely involving length validation, offset calculation, or recursive structure parsing, which results in a crash during the dissection process.\nWhen the dissector encounters a malformed MBIM packet, it fails to perform adequate boundary checks on variable-length parameters or nested structures defined within the protocol specification. This triggers a memory corruption event or an out-of-bounds read/write operation, forcing the application to terminate execution to prevent unpredictable state corruption. The lack of robust exception handling within the parsing logic allows the crash to propagate, resulting in a full service disruption.\nThe attack flow proceeds as follows: First, an attacker identifies the target interface or service running the vulnerable dissector. Second, the attacker crafts a malicious MBIM payload containing intentionally malformed headers or inconsistent field values designed to exploit the specific logic path that lacks bounds checking. Third, this payload is injected into the communication stream, either via physical hardware interaction or over a network segment that the dissector monitors. Upon receipt, the dissector attempts to parse the corrupted structure; the parsing engine reaches an error state that is not caught by the surrounding logic, leading to the crash.\nThis issue affects versions 4.6.0-4.6.8 and 4.4.0-4.4.18. Given the nature of protocol dissectors, this vulnerability is generally reachable remotely, meaning any source capable of sending frames to the vulnerable component can trigger the DoS. There is no requirement for user interaction or authentication. The impact is specifically a crash and the subsequent denial of service, though the nature of such flaws often invites further research into potential remote code execution (RCE) via memory corruption primitives if the dissector environment is not sufficiently isolated."
}