Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-60109

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior authentication.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zeek:zeek:*:*:*:*:*:*:*:*
Версия до 8.0.9 (исключая)

EPSS

Процентиль: 40%
0.00502
Низкий

7.5 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 7.5
debian
28 дней назад

Zeek before 8.0.9 contains a null pointer dereference vulnerability in ...

CVSS3: 7.5
github
28 дней назад

Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior authentication.

EPSS

Процентиль: 40%
0.00502
Низкий

7.5 High

CVSS3

Дефекты

CWE-476