CVE-2025-68382

Published: Dic 18, 2025 Last Modified: Dic 23, 2025
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,5
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0005
Percentile
0,2th
Updated

EPSS Score Trend (Last 87 Days)

125

Out-of-bounds Read

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Availability Other
Potential Impacts:
Read Memory Bypass Protection Mechanism Dos: Crash, Exit, Or Restart Varies By Context
Applicable Platforms
Languages: C, C++, Memory-Unsafe
Technologies: ICS/OT
View CWE Details
Application

Packetbeat by Elasticsearch

Version Range Affected
From 9.2.0 (inclusive)
To 9.2.3 (exclusive)
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Packetbeat by Elasticsearch

Version Range Affected
From 8.0.0 (inclusive)
To 8.19.9 (exclusive)
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Packetbeat by Elasticsearch

Version Range Affected
From 7.0.0 (inclusive)
To 7.17.29 (inclusive)
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Packetbeat by Elasticsearch

Version Range Affected
From 9.0.0 (inclusive)
To 9.1.9 (exclusive)
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://discuss.elastic.co/t/packetbeat-8-19-9-9-1-9-and-9-2-3-security-update-…