« Volver al listado

CVE-2017-15192

Estado: ModificadaAlta (7.5)—

En Wireshark desde la versión 2.4.0 hasta la 2.4.1 y desde la 2.2.0 hasta la 2.2.9, el disector BT ATT podría cerrarse inesperadamente. Esto se abordó en epan/dissectors/packet-btatt.c considerando un caso en el que no todos los paquetes BTATT tienen el mismo nivel de encapsulación.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-15192",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-10T21:29:00.460",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/101235",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14049",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://code.wireshark.org/review/23470",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=3689dc1db36037436b1616715f9a3f888fc9a0f6",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.wireshark.org/security/wnpa-sec-2017-42.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/101235",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14049",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.wireshark.org/review/23470",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=3689dc1db36037436b1616715f9a3f888fc9a0f6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.wireshark.org/security/wnpa-sec-2017-42.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level."
    },
    {
      "lang": "es",
      "value": "En Wireshark desde la versión 2.4.0 hasta la 2.4.1 y desde la 2.2.0 hasta la 2.2.9, el disector BT ATT podría cerrarse inesperadamente. Esto se abordó en epan/dissectors/packet-btatt.c considerando un caso en el que no todos los paquetes BTATT tienen el mismo nivel de encapsulación."
    }
  ],
  "lastModified": "2026-06-17T01:07:20.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32F65580-D1F4-4ABC-A358-545BF29D8089"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6568A81-BE0B-4AEF-808C-74CD0C2EE9FD"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFFBDC3C-3701-4890-8AA5-AD96EB528F05"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB13134E-A2E8-46A5-88B2-E2C2C24B6780"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FC9883C-4B22-4C81-8C51-932BBF2CB3B8"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F0E7715-61FE-404D-834F-3EFC75423292"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDFF360E-2CE4-4722-83E6-08B811852422"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3B1F0CD-ACD8-4583-AEF6-6EEEFBE397C7"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "405C0606-46BB-4932-BBE4-6ADC12C1FE44"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.2.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "639FCB7A-7D1B-4F6B-8CC5-E246961E4321"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "999B2C81-6C7D-443F-9FE8-F250D9C99735"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "354F160E-7CA9-4D8E-A447-42E500922EB2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}