CVE-2025-68388
Discovered by AISLEPUBLISHEDCWE-770
Description
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.
CVSS Base Scores
CVSS v3.1(Primary)
5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| Elastic | Packetbeat | 8.6.0 | affected |
| Elastic | Packetbeat | 9.0.0 | — |
| Elastic | Packetbeat | 9.2.0 | — |