Sceawere

Vulnerability Detail

CVE-2026-96417UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RF4CE Dissector Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:16.353Z",
  "pubdate": "2026-09-29T10:17:16.353Z",
  "executiveSummary": "A vulnerability exists in the RF4CE protocol dissector, leading to a denial-of-service condition through application crashing.\nThe vulnerability affects versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe flaw allows a remote, unauthenticated attacker to disrupt system availability by sending malformed or specifically crafted RF4CE protocol traffic.\nUpon processing the malicious input, the dissector fails to handle the data correctly, triggering an unrecoverable exception that halts the process.\nThis vulnerability poses a significant risk to the availability and stability of network analysis tools and devices implementing the RF4CE protocol stack.\nExploitation requires no special privileges or authentication, making it a critical concern for systems exposed to untrusted RF4CE traffic.",
  "technicalDetails": "The vulnerability resides within the RF4CE protocol dissector component responsible for parsing and analyzing radio frequency frames. The root cause is a deficiency in input validation and error handling logic, which fails to safely process anomalous protocol structures.\nWhen the dissector encounters malformed packets, it fails to perform adequate bounds checking or state validation before execution, leading to memory corruption or an illegal memory access condition.\nThe attack flow initiates when an attacker transmits a crafted RF4CE payload over the air or via the network interface to a target implementation. As the vulnerable dissector processes the incoming traffic, the crafted packet triggers an exception during the parsing phase. This exception is not caught by the application's error handling routines, resulting in a crash of the service or the process responsible for frame dissection.\nBecause the RF4CE protocol is utilized in various low-power wireless applications, the exposure extends to any infrastructure utilizing the affected dissector versions to decode protocol traffic. The impact is strictly related to availability; once the crash occurs, the monitoring or communication capability of the affected system is nullified until a manual or automated restart occurs.\nThis vulnerability does not require authentication or elevated privileges, as the dissection process typically occurs upon initial frame ingestion. The payload behavior is specifically designed to exploit the parsing logic, likely triggering an out-of-bounds read or write during packet header or payload dissection. Post-exploitation, the attacker achieves a persistent denial-of-service state for the affected component, effectively blinding the monitoring tool or causing a system-wide stall if the dissector is tightly integrated into the primary communication stack."
}