Sceawere

Vulnerability Detail

CVE-2026-95393UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CSN.1 Dissector Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-29T10:17:15.610Z",
  "pubdate": "2026-09-29T10:17:15.610Z",
  "executiveSummary": "A vulnerability exists within the CSN.1 protocol dissector affecting specific versions of the software product. This vulnerability is classified as a Denial of Service (DoS) flaw.\nThe issue arises from improper handling of malformed or unexpected CSN.1 protocol data, which triggers a crash within the dissector component.\nImpact includes the termination of the parsing process, leading to a service disruption. If the dissector is utilized by a critical service, this can result in the complete unavailability of network traffic analysis or protocol handling functionality.\nThe vulnerability is reachable via the network, allowing a remote, unauthenticated attacker to supply a specially crafted packet that triggers the crash.\nNo specific privileges are required to initiate the attack, as the dissector processes incoming data streams directly. Successful exploitation does not lead to remote code execution but forces an immediate application fault.",
  "technicalDetails": "The vulnerability resides within the CSN.1 protocol dissector, which is responsible for parsing and translating bit-level protocol definitions into structured formats for analysis. The dissector fails to safely handle non-compliant or malformed input streams, leading to a memory access violation or an unhandled exception.\nRoot Cause: The flaw is rooted in an logic error in the state machine or the bit-field validation routines of the CSN.1 dissector. When an incoming packet contains malformed data or violates the expected structural constraints defined by the CSN.1 specification, the dissector fails to perform bounds checking or type validation correctly, leading to an attempt to access invalid memory or an infinite loop resulting in resource exhaustion.\nAffected Versions: The vulnerability impacts versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nAttack Flow: An attacker performs the exploit by injecting a malicious packet into the network segment monitored or processed by the target application. Because the dissector automatically parses inbound traffic, the malformed CSN.1 structures are processed without prior authentication or privilege verification. Upon encountering the trigger sequence, the dissector component crashes.\nPost-Exploitation: The primary impact is the immediate cessation of the dissector’s functionality. If the software is configured to handle multiple streams, the crash may result in a complete service outage. This requires a manual restart or process recovery mechanism, as the dissector cannot recover from the fault autonomously.\nTechnical Complexity: The exploitation requires knowledge of the target's protocol parsing logic to craft a packet that successfully triggers the crash condition while conforming enough to pass initial structural filters. Because the vulnerability involves a parsing error, it falls into the category of memory-corruption or logic-based instability resulting from input sanitization failures."
}
CVE-2026-95393: CSN.1 Dissector Denial of Service (MEDIUM Severity, CVSS: 4.7) | Sceawere