Sceawere

Vulnerability Detail

CVE-2026-96420UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Toshiba File Parser DoS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-126: Buffer Over-read
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-29T10:17:16.790Z",
  "pubdate": "2026-09-29T10:17:16.790Z",
  "executiveSummary": "A denial of service (DoS) vulnerability exists within the file parsing component of affected Toshiba products. This flaw enables an unauthenticated attacker to induce an application crash by supplying a specially crafted file.\nThe vulnerability originates from improper handling of specific file structures during the parsing process, leading to memory corruption or exception states that terminate the service. The impact is restricted to service availability, potentially resulting in operational downtime for the affected system.\nThe issue affects specific ranges of versions: 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. There are no authentication requirements for exploitation, provided the attacker can submit a file to the vulnerable parsing engine. Organizations relying on these versions face moderate risk due to the potential for service disruption, necessitating proactive patch management once updates become available.",
  "technicalDetails": "The vulnerability resides within the Toshiba file parser, a component responsible for ingesting, validating, and processing input files. The root cause is categorized as an improper input validation error, where the parser fails to adequately sanitize or verify the integrity and structure of input files.\nWhen the parser encounters a malformed file containing specific structural anomalies, it fails to manage the resulting internal state transitions correctly. This typically occurs when the parser attempts to read out-of-bounds memory or triggers an unhandled exception due to unexpected data pointers or metadata discrepancies within the input file. The parser's failure to gracefully recover from these input-driven anomalies forces the host process to terminate, resulting in a denial of service.\nThe attack flow involves the following stages: First, an attacker identifies an endpoint or interface that utilizes the Toshiba file parser for data ingestion. Second, the attacker generates a malicious file designed to trigger the identified parsing logic, specifically targeting areas where the parser lacks robust bounds checking or input validation. Third, the attacker transmits this file to the target system. Upon ingestion, the parser's internal logic initiates processing, leading to the triggering of the vulnerability. The crash of the parsing component often leads to a cascade failure or service hang, rendering the application unavailable until human intervention or automated restart procedures are executed.\nAffected versions include 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. The vulnerability is exploitable without authentication, meaning any user or process with access to the input interface can trigger the failure. This exposure is critical if the parsing interface is network-facing or accessible to untrusted users. Because the parsing engine is typically a critical dependency, its failure can lead to significant post-exploitation impacts, including total loss of service functionality, data processing backlogs, and the need for manual service restoration. The vulnerability does not appear to involve arbitrary code execution; rather, it is strictly limited to an availability impact through software instability."
}