CVE-2011-1591 describes a stack-based buffer overflow in the DECT dissector of Wireshark versions 1.4.x before 1.4.5. This vulnerability allows remote attackers to execute arbitrary code by providing a specially crafted .pcap file. With a CVSS score of 9.3, it is considered critical, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though requiring medium attack complexity. While not listed on the KEV catalog, exploit code is publicly available, including multiple Metasploit modules and ExploitDB entries demonstrating both local and remote exploitation. Despite the availability of exploits, there is no evidence of active exploitation in the wild, and community discussion and media coverage are minimal. The EPSS score of 0.77213 suggests a higher than average probability of exploitation compared to other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.0:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.2:*:*:*:*:*:*:* | ||
1.4.3CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.3:*:*:*:*:*:*:* | ||
1.4.4CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:1.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.