Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CWireshark
APPWireshark0.100.10.10.10.100.10.110.10.120.10.130.10.140.10.20.10.30.10.40.10.50.10.60.10.70.10.80.10.9+ 27 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2018-6836CRITICAL9.8PL ✓same product
Wireshark: operacja free na niezainicjowanym adresie w netmonrec_comment_destroy
CVE-2026-76886HIGH8.1same product
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76880HIGH7.5same product
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76879HIGH7.5same product
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76928HIGH7.5same product
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service