CVE-2025-9386
published 2025-08-24CVE-2025-9386: A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.0th percentile
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| appneta | tcpreplay | — | — |
| appneta | tcpreplay | — | — |
| broadcom | tcpreplay | <= 4.5.1 | — |
| broadcom | tcpreplay | >= 0 < 4.5.2-1 | 4.5.2-1 |
| debian | tcpreplay | < tcpreplay 4.5.2-1 (forky) | tcpreplay 4.5.2-1 (forky) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-9386: tcpreplay - A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted el...
vendor_debian·2025·CVSS 4.8
CVE-2025-9386 [MEDIUM] CVE-2025-9386: tcpreplay - A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted el...
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.5.2-1)
sid: resolved (fixed in 4.5.2-1)
trixie: open
Citrix
Citrix Security Bulletin CTX218775
vendor_citrix·CVSS 7.9
CVE-2016-9379 [HIGH] Citrix Security Bulletin CTX218775
Citrix Security Bulletin CTX218775
CVE References: CVE-2016-9379, CVE-2016-9380, CVE-2016-9381, CVE-2016-9382, CVE-2016-9383, CVE-2016-9385, CVE-2016-9386, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
OSV
CVE-2025-9386: A vulnerability has been found in appneta tcpreplay up to 4
osv·2025-08-24·CVSS 4.8
CVE-2025-9386 [MEDIUM] CVE-2025-9386: A vulnerability has been found in appneta tcpreplay up to 4
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.
GHSA
GHSA-722m-c232-cwqp: A vulnerability has been found in appneta tcpreplay up to 4
ghsa_unreviewed·2025-08-24
CVE-2025-9386 [MEDIUM] CWE-119 GHSA-722m-c232-cwqp: A vulnerability has been found in appneta tcpreplay up to 4
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to resolve this issue. You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-24
Published