CVE-2015-6244
published 2015-08-24CVE-2015-6244: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.24%
86.8th percentile
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.12.7+g7fc8978-1 (bookworm) | wireshark 1.12.7+g7fc8978-1 (bookworm) |
| oracle | linux | — | — |
| oracle | solaris | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.12.7+g7fc8978-1 | 1.12.7+g7fc8978-1 |
| wireshark | wireshark | >= 0 < 1.12.7+g7fc8978-1 | 1.12.7+g7fc8978-1 |
| wireshark | wireshark | >= 0 < 1.12.7+g7fc8978-1 | 1.12.7+g7fc8978-1 |
| wireshark | wireshark | >= 0 < 1.12.7+g7fc8978-1 | 1.12.7+g7fc8978-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f943-fr9x-gj9q: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security
ghsa_unreviewed·2022-05-13
CVE-2015-6244 [MEDIUM] CWE-20 GHSA-f943-fr9x-gj9q: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
OSV
CVE-2015-6244: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security
osv·2015-08-24·CVSS 4.3
CVE-2015-6244 [MEDIUM] CVE-2015-6244: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Red Hat
wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
vendor_redhat·2015-08-11·CVSS 4.3
CVE-2015-6244 [MEDIUM] CWE-130 wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Statement: This issue did not affect the version of wireshark as shipped with Red Hat Enterprise Linux 5. This issue affects the verison of wireshark as shipped with Red Hat Enterprise Linux 6. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 6.
Mitigation: This flaw can be mitigated in wireshark by disabling the ZigBee protocol dissector. In wiresha
Debian
CVE-2015-6244: wireshark - The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in th...
vendor_debian·2015·CVSS 4.3
CVE-2015-6244 [MEDIUM] CVE-2015-6244: wireshark - The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in th...
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.7+g7fc8978-1)
bullseye: resolved (fixed in 1.12.7+g7fc8978-1)
forky: resolved (fixed in 1.12.7+g7fc8978-1)
sid: resolved (fixed in 1.12.7+g7fc8978-1)
trixie: resolved (fixed in 1.12.7+g7fc8978-1)
No detection rules found.
No public exploits indexed.
arXiv
Mission Aware Cyber-physical Security
arxiv_fulltext·2025-10-23
Mission Aware Cyber-physical Security
Mission Aware Cyber-physical Security
[1]Georgios Bakirtzis
[2]Bryan Carter
[3]Cody H. Fleming
[4]Carl R. Elks
[1]LTCI, Télécom Paris, Institut Polytechnique de Paris
[2]University of Virginia
[3]Iowa State University
[4]Virginia Commonwealth University
Cody Fleming PhD, Iowa State University, Ames, Iowa, 50011, USA
[email protected]
## Abstract
Perimeter cybersecurity, while essential, has proven insufficient against sophisticated, coordinated, and cyber-physical attacks. In contrast, mission-centric cybersecurity emphasizes finding evidence of attack impact on mission success, allowing for targeted resource allocation to mitigate vulnerabilities and protect critical assets. Mission Aware is a systems-theoretic cybersecurity analysis that identifies components which, if compromised,
arXiv
A Model-Based Approach to Security Analysis for Cyber-Physical Systems
arxiv_fulltext·2018-06-10
A Model-Based Approach to Security Analysis for Cyber-Physical Systems
## Abstract
Evaluating the security of cyber-physical systems throughout their life cycle is necessary to assure that they can be deployed and operated in safety-critical applications, such as infrastructure, military, and transportation. Most safety and security decisions that can have major effects on mitigation strategy options after deployment are made early in the system's life cycle. To allow for a vulnerability analysis before deployment, a sufficient well-formed model has to be constructed. To construct such a model we produce a taxonomy of attributes; that is, a generalized schema for system attributes. This schema captures the necessary specificity that characterizes a possible real system and can also map to the attack vector space associated with the model's attributes. In thi
Bugzilla
CVE-2015-6244 wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
bugzilla·2015-08-13·CVSS 4.3
CVE-2015-6244 [MEDIUM] CVE-2015-6244 wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
CVE-2015-6244 wireshark: ZigBee dissector crash (wnpa-sec-2015-24)
It was reported that Wireshark's ZigBee dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This flaw is fixed in the following Wireshark versions: 1.12.7.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11389
External References:
https://www.wireshark.org/security/wnpa-sec-2015-24
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1253364]
---
wireshark-1.12.7-2.fc22 has been pushed to the Fedora 22 testing repository. If problems still persist, please make note of it in this bug report.\nIf you want to test the update, you can install
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168837.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165509.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00053.htmlhttp://www.debian.org/security/2015/dsa-3367http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76383http://www.securitytracker.com/id/1033272http://www.wireshark.org/security/wnpa-sec-2015-24.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11389https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=31571144be5f03f054a9c7e195b38c2f5792fe54https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=43c2e5769a17f0945fdcdabe35204a13ca9bbc85https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=655b0dc623e29da212be3e205314624fe3182562http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168837.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165509.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00053.htmlhttp://www.debian.org/security/2015/dsa-3367http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/76383http://www.securitytracker.com/id/1033272http://www.wireshark.org/security/wnpa-sec-2015-24.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11389https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=31571144be5f03f054a9c7e195b38c2f5792fe54https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=43c2e5769a17f0945fdcdabe35204a13ca9bbc85https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=655b0dc623e29da212be3e205314624fe3182562
2015-08-24
Published