Sceawere

Vulnerability Detail

CVE-2026-96415UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Catapult DCT2000 Dissector DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-121: Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:16.047Z",
  "pubdate": "2026-09-29T10:17:16.047Z",
  "executiveSummary": "A denial-of-service (DoS) vulnerability exists within the Catapult DCT2000 protocol dissector, affecting versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe flaw allows an unauthenticated remote attacker to cause a crash of the dissector component by supplying malformed protocol data.\nThe vulnerability resides in the way the dissector parses incoming Catapult DCT2000 traffic. Successful exploitation results in the abnormal termination of the dissection process, effectively disabling traffic analysis or monitoring capabilities provided by the application.\nBecause the crash impacts the parsing engine, this vulnerability poses a significant risk to availability in environments relying on the DCT2000 dissector for network diagnostics or security monitoring.\nThe attack is typically triggered by injecting a crafted packet into the monitored network stream, requiring no specific user interaction or authentication from the victim perspective.",
  "technicalDetails": "The Catapult DCT2000 protocol dissector is susceptible to a denial-of-service condition due to improper handling of anomalous input during the protocol decoding process. The vulnerability stems from logic errors within the parsing logic, likely related to length validation, buffer handling, or state management when processing encapsulated or malformed DCT2000 frames.\nThe root cause is identified as an inability of the dissector to gracefully handle unexpected input sequences, leading to an unhandled exception or an illegal memory access. When the dissector encounters a specially crafted packet that deviates from the expected protocol specifications, it triggers a crash of the process responsible for decoding the traffic.\nAttack flow typically begins when a malicious actor transmits a crafted Catapult DCT2000 frame directed at the network interface or packet capture stream monitored by the vulnerable software. Upon receipt, the dissector attempts to interpret the payload. If the payload contains specific fields or data structures that trigger the underlying code defect (e.g., triggering a null pointer dereference, an out-of-bounds memory read, or a stack exhaustion condition), the dissector terminates abruptly.\nBecause the dissector component is often a foundational piece of infrastructure for analysis tools, the termination of this process disrupts the application's ability to decode further traffic, resulting in a persistent denial-of-service state until the service is manually restarted.\nAffected versions include 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. The attack does not require authentication or elevated privileges, as the dissector processes traffic automatically at the link or transport layer. The exploit is facilitated by the network exposure of the target system, allowing any party capable of sending packets that the dissector is configured to parse to trigger the crash condition. There is no evidence of arbitrary code execution; however, the impact is severe for availability, as it effectively blinds security monitoring tools or diagnostic utilities relying on this specific dissector component."
}
CVE-2026-96415: Catapult DCT2000 Dissector DoS (MEDIUM Severity, CVSS: 5.5) | Sceawere