CVE-2017-13017 describes a critical buffer over-read vulnerability (CWE-125) in the DHCPv6 parser of tcpdump versions prior to 4.9.2, specifically within the dhcp6opt_print() function. This flaw carries a CVSSv3 score of 9.8 (Critical), indicating it is easily exploitable over the network with no user interaction, leading to high impacts on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community. Its low EPSS score and inactive status on the Hot List suggest limited current exploitation, despite its high theoretical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.