Vulnerability Description
A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isc | Kea | >= 1.4.0, <= 1.5.0 |
Related Weaknesses (CWE)
References
- https://kb.isc.org/docs/cve-2019-6472Vendor Advisory
- https://kb.isc.org/docs/cve-2019-6472Vendor Advisory
FAQ
What is CVE-2019-6472?
CVE-2019-6472 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
How severe is CVE-2019-6472?
CVE-2019-6472 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6472?
Check the references section above for vendor advisories and patch information. Affected products include: Isc Kea.