CVE-2025-9649
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-369
División por cero
Fecha de publicación:
29/08/2025
Última modificación:
09/10/2025
Descripción
*** Pendiente de traducción *** A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 4.5.3-beta3 is recommended to address this issue. It is advisable to upgrade the affected component. The vendor confirms in a GitHub issue reply: "Was able to reproduce in 6fcbf03 but NOT 4.5.3-beta3."
Impacto
Puntuación base 4.0
4.80
Gravedad 4.0
MEDIA
Puntuación base 3.x
3.30
Gravedad 3.x
BAJA
Puntuación base 2.0
1.70
Gravedad 2.0
BAJA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:broadcom:tcpreplay:4.5.1:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://drive.google.com/file/d/16QQtZvUrMbF-i_1cGt5hNWmkn-YVyBOM/view?usp=sharing
- https://github.com/appneta/tcpreplay/issues/968
- https://github.com/appneta/tcpreplay/issues/968#issuecomment-3226338070
- https://vuldb.com/?ctiid_321855=
- https://vuldb.com/?id_321855=
- https://vuldb.com/?submit_630493=
- https://vuldb.com/?submit_630494=



