CVE-2026-5404 - Vulnerability Analysis
MediumCVSS: 4.7Last Updated: May 1, 2026
Wireshark - Denial of Service
Published: May 1, 2026Updated: May 1, 2026PoC Available
Overview
Wireshark 4.4.0 to 4.4.14 and 4.6.0 to 4.6.4 contain a denial of service caused by a crash in the K12 RF5 file parser, letting remote attackers cause application crash, exploit requires crafted file input.
Severity & Score
Severity: Medium
CVSS Score: 4.7
Impact
Remote attackers can cause application crash leading to denial of service.
Mitigation
Update to a version later than 4.6.4 or 4.4.14.
References
Related Resources
Details
- CVE ID
- CVE-2026-5404
- Severity
- Medium
- CVSS Score
- 4.7
- Type
- undefined
- Status
- confirmed
CWE
- CWE-120
CVSS Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H