PT-2026-43270 · Unknown · Fastnetmon Community Edition
Pavel-Odintsov
·
Published
2026-05-26
·
Updated
2026-05-26
·
CVE-2026-48683
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FastNetMon Community Edition versions prior to 1.2.10
Description
An out-of-bounds read exists in the NetFlow v9 data flowset processor within the
src/netflow plugin/netflow v9 collector.cpp file. The Data template branch iterates over flow records without performing a per-iteration bounds check against the packet end pointer, unlike the Options template branch which correctly validates the packet length. Because template definitions are sent via unauthenticated UDP by a network peer, an attacker can craft malicious templates to force the parser to read arbitrary memory beyond the packet buffer, potentially leading to sensitive memory leakage or a system crash.Recommendations
Update to a version later than 1.2.9.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastnetmon Community Edition