CVE-2026-3201 - Vulnerability Analysis
MediumCVSS: 4.7Last Updated: February 26, 2026
Wireshark - Denial of Service
Published: February 25, 2026Updated: February 26, 2026PoC Available
Overview
Wireshark 4.4.0 to 4.4.13 and 4.6.0 to 4.6.3 contain a denial of service caused by memory exhaustion in the USB HID protocol dissector, letting attackers cause application crash, exploit requires crafted USB HID packets.
Severity & Score
Severity: Medium
CVSS Score: 4.7
Impact
Attackers can cause Wireshark to crash, resulting in denial of service.
Mitigation
Update to a version later than 4.6.3 or 4.4.13.
References
Related Resources
Details
- CVE ID
- CVE-2026-3201
- Severity
- Medium
- CVSS Score
- 4.7
- Type
- denial_of_service
- Status
- confirmed
CWE
- CWE-1325
- CWE-770
CVSS Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H