CVE-2019-6472 is a vulnerability in ISC Kea
Published on October 16, 2019
A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate
A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH
Products Associated with CVE-2019-6472
Want to know whenever a new CVE is published for ISC Kea? stack.watch will email you.
Affected Versions
ISC Kea:- Version 1.4.0 to 1.5.0 is affected.
- Version 1.6.0-beta1 is affected.
- Version 1.6.0-beta2 is affected.
Exploit Probability
EPSS
0.68%
Percentile
71.23%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.