CVE-2025-9384: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference
A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpeditpostargs of the file /src/tcpedit/parseargs.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrading the affected component is advised. The vendor explains, that he was "[a]ble to reproduce in 6fcbf03 but not in 4.5.2-beta2".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9384?
CVE-2025-9384 is classified as a high-severity vulnerability due to its potential for a local exploit resulting in null pointer dereference.
How do I fix CVE-2025-9384?
To mitigate CVE-2025-9384, upgrade to AppNeta tcpreplay version 4.5.2 or later.
Who is affected by CVE-2025-9384?
CVE-2025-9384 affects users of AppNeta tcpreplay versions up to and including 4.5.1.
What type of vulnerability is CVE-2025-9384?
CVE-2025-9384 is a null pointer dereference vulnerability residing in the tcpedit_post_args function.
Can CVE-2025-9384 be exploited remotely?
CVE-2025-9384 can only be exploited locally, requiring local access to the affected system.