CVE-2017-13046 is a critical buffer over-read vulnerability (CWE-125) in the BGP parser of tcpdump versions prior to 4.9.2, specifically within the print-bgp.c:bgp_attr_print() function. This flaw allows an unauthenticated attacker to remotely execute arbitrary code, compromise data, or cause a denial of service due to its CVSS v3.0 score of 9.8 (CRITICAL). While no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV catalog entry exists, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Despite its high severity, there is no evidence of active exploitation, and it is not on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.