Tcpreplay

Vendor:

First CVE: Jan 23, 2017 · Active for 9 years

50
Total CVEs
More Total CVEs than 98% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tcpreplay over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Sep 23, 2025
304 days ago

CVE Severity & Scoring

Tcpreplay50 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local32 (64.0%)
Network18 (36.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None22 (44.0%)
Unknown0 (0.0%)
Required28 (56.0%)
Privileges Required
Low5 (10.0%)
High0 (0.0%)
None45 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.
Sep 12, 20177.838NOYES
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service o
Oct 17, 20189.831NONO
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
Mar 26, 20227.828NONO
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
Mar 26, 20227.828NONO
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
May 8, 20209.128NONO
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
Aug 18, 20227.826NONO
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022
Aug 18, 20227.826NONO
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-2794
Aug 18, 20227.826NONO
Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c.
Apr 12, 20227.826NONO
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap
Feb 17, 20197.826NONO

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For Tcpreplay

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.5.146.70.4%00
4.4.436.50.5%00
4.4.387.31.3%00
4.4.1117.30.9%00
4.3.425.50.7%00
4.3.327.52.6%00
4.3.225.50.7%00
4.3.137.81.2%00
4.3.067.11.5%00
3.4.417.83.6%01