CVE-2022-3724: High severity wireshark vulnerability
Published Dec 9, 2022
·Updated
Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
Affected Software
4 affected components
Wireshark Wireshark>=3.6.0<=3.6.8
Microsoft Windows
All of the following
Wireshark Wireshark>=3.6.0<=3.6.8
Microsoft Windows
Event History
Dec 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-3724?
CVE-2022-3724 is a vulnerability in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 that allows denial of service via packet injection or crafted capture file on Windows.
2
How can I exploit CVE-2022-3724?
CVE-2022-3724 can be exploited by injecting packets or using a crafted capture file.
3
What is the severity of CVE-2022-3724?
CVE-2022-3724 has a severity rating of 7.5 (high).
4
Is Wireshark affected by CVE-2022-3724?
Yes, Wireshark versions 3.6.0 to 3.6.8 are affected by CVE-2022-3724.
5
How do I fix CVE-2022-3724?
To fix CVE-2022-3724, update to a version of Wireshark that is not affected by the vulnerability.