CVE-2026-3203 describes a denial-of-service vulnerability in Wireshark versions 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13, specifically within the RF4CE Profile protocol dissector. This flaw carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity, leading to a complete loss of availability for the affected system. While there is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, < 4.4.14CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.4CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.