3.3
CVSSv2

CVE-2019-6472

Published: 16/10/2019 Updated: 05/12/2019
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc kea

isc kea 1.6.0

Vendor Advisories

Debian Bug report logs - #936040 isc-kea: CVE-2019-6472 CVE-2019-6473 CVE-2019-6474 Package: src:isc-kea; Maintainer for src:isc-kea is Kea <isc-kea@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 29 Aug 2019 11:09:02 UTC Severity: grave Tags: security, upstream Found in versio ...
The Kea DHCPv6 server, which can exit with an assertion failure if the DHCPv6 server process receives a request containing DUID value which is too large ...