« Volver al listado

CVE-2012-5237

Estado: ModificadaBaja (3.3)—

La función dissect_hsrp en epan/dissectors/packet-hsrp.c en el "dissector" HSRP en Wireshark v1.8.x anteriores a v1.8.3 permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de un paquete mal formado.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5237",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-04T19:55:00.870",
  "references": [
    {
      "url": "http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-hsrp.c?r1=44454&r2=44453&pathrev=44454",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc?view=revision&revision=44454",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/85884",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/55754",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1027604",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wireshark.org/security/wnpa-sec-2012-26.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7581",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79009",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14992",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-hsrp.c?r1=44454&r2=44453&pathrev=44454",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc?view=revision&revision=44454",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/85884",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/55754",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027604",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wireshark.org/security/wnpa-sec-2012-26.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7581",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79009",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14992",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet."
    },
    {
      "lang": "es",
      "value": "La función dissect_hsrp en epan/dissectors/packet-hsrp.c en el \"dissector\" HSRP en Wireshark v1.8.x anteriores a v1.8.3 permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de un paquete mal formado."
    }
  ],
  "lastModified": "2026-06-16T23:46:29.627",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "606DF728-1DA6-4989-B40A-44471CC677DB"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F824AE6B-B087-4C69-8F73-7B146920FC3C"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6702EAA1-7FBD-4755-B7C2-C2B3A1AFF142"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}