Elastic Packetbeat
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*
- >= 8.19.0, < 8.19.11
- >= 9.2.0, < 9.2.5
A denial-of-service vulnerability has been identified in Elastic Packetbeat versions 8.19.11 and 9.2.5. The issue arises from improper validation of array indices in multiple protocol parser components, allowing an attacker to manipulate input data and cause out-of-bounds read operations. This exploitation can lead to application crashes or resource exhaustion. To trigger this vulnerability, an attacker must send specially crafted, malformed network packets to a monitored interface, requiring them to be on the same network segment as the Packetbeat deployment or to control traffic routed to the monitored interfaces.
Exploitation of this vulnerability can cause application crashes or resource exhaustion, leading to a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.