cbcvebase.
CVE-2023-27784
published 2023-03-16

CVE-2023-27784: An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.47%
70.5th percentile
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

Affected

9 ranges
VendorProductVersion rangeFixed in
broadcomtcpreplay
broadcomtcpreplay>= 0 < 4.4.4-14.4.4-1
broadcomtcpreplay>= 0 < 4.4.4-14.4.4-1
broadcomtcpreplay>= 0 < 3.4.4-2+deb8u1ubuntu0.1~esm33.4.4-2+deb8u1ubuntu0.1~esm3
broadcomtcpreplay>= 0 < 4.2.6-1ubuntu0.1~esm54.2.6-1ubuntu0.1~esm5
broadcomtcpreplay>= 0 < 4.3.2-1ubuntu0.1~esm34.3.2-1ubuntu0.1~esm3
broadcomtcpreplay>= 0 < 4.3.4-1ubuntu0.1~esm24.3.4-1ubuntu0.1~esm2
broadcomtcpreplay>= 0 < 4.4.4-1ubuntu0.1~esm14.4.4-1ubuntu0.1~esm1
debiantcpreplay< tcpreplay 4.4.4-1 (forky)tcpreplay 4.4.4-1 (forky)

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.