Tcpreplay
Vendor:
First CVE: Jan 23, 2017 · Active for 9 years
50
Total CVEs
More Total CVEs than 98% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tcpreplay over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Sep 23, 2025
304 days ago
CVE Severity & Scoring
Tcpreplay50 CVEs
30%
66%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local32 (64.0%)
Network18 (36.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None22 (44.0%)
Unknown0 (0.0%)
Required28 (56.0%)
Privileges Required
Low5 (10.0%)
High0 (0.0%)
None45 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14266HIGH tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160. | Sep 12, 2017 | 7.8 | 38 | NO | YES |
CVE-2018-18408CRITICAL A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service o | Oct 17, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-27942HIGH tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. | Mar 26, 2022 | 7.8 | 28 | NO | NO |
CVE-2022-27940HIGH tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. | Mar 26, 2022 | 7.8 | 28 | NO | NO |
CVE-2020-12740CRITICAL tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c. | May 8, 2020 | 9.1 | 28 | NO | NO |
CVE-2022-37049HIGH The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942. | Aug 18, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-37048HIGH The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022 | Aug 18, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-37047HIGH The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-2794 | Aug 18, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-27418HIGH Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c. | Apr 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-8377HIGH An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap | Feb 17, 2019 | 7.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Tcpreplay
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5.1 | 4 | 6.7 | 0.4% | 0 | 0 |
| 4.4.4 | 3 | 6.5 | 0.5% | 0 | 0 |
| 4.4.3 | 8 | 7.3 | 1.3% | 0 | 0 |
| 4.4.1 | 11 | 7.3 | 0.9% | 0 | 0 |
| 4.3.4 | 2 | 5.5 | 0.7% | 0 | 0 |
| 4.3.3 | 2 | 7.5 | 2.6% | 0 | 0 |
| 4.3.2 | 2 | 5.5 | 0.7% | 0 | 0 |
| 4.3.1 | 3 | 7.8 | 1.2% | 0 | 0 |
| 4.3.0 | 6 | 7.1 | 1.5% | 0 | 0 |
| 3.4.4 | 1 | 7.8 | 3.6% | 0 | 1 |