CVE-2025-9385: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free
A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fixipv6checksums of the file editpacket.c of the component tcprewrite. This manipulation causes use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version 4.5.2-beta3 is sufficient to fix this issue. It is advisable to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9385?
CVE-2025-9385 is classified as a high severity vulnerability due to potential exploitation leading to use after free conditions.
How do I fix CVE-2025-9385?
To fix CVE-2025-9385, update AppNeta tcpreplay to version 4.5.2 or later.
What components are affected by CVE-2025-9385?
CVE-2025-9385 affects the tcprewrite component of AppNeta tcpreplay specifically in the fix_ipv6_checksums function of edit_packet.c.
Who can exploit CVE-2025-9385?
CVE-2025-9385 can only be exploited through local execution, meaning local users have the potential to exploit this vulnerability.
What kind of attack is associated with CVE-2025-9385?
CVE-2025-9385 is associated with a use after free attack, which can lead to unauthorized access or data corruption.