PT-2026-43271 · Unknown · Fastnetmon Community Edition
Published
2026-05-26
·
Updated
2026-05-27
·
CVE-2026-48684
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
FastNetMon Community Edition versions prior to 1.2.10
Description
An out-of-bounds read exists in the NetFlow v9 options template parser. In the
process netflow v9 options template() function, the scope parsing loop iterates until scopes offset reaches the attacker-controlled option scope length value without validating that the memory access remains within the flowset. A similar issue occurs in the options field loop involving option length. Additionally, option scope length is not verified to be a multiple of sizeof(netflow9 template flowset record t), which may lead to misaligned reads. This allows an attacker to trigger reads beyond the end of the UDP packet buffer.Recommendations
Update to version 1.2.10 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastnetmon Community Edition