VYPR
Unrated severityNVD Advisory· Published Dec 15, 2024· Updated Dec 16, 2024

CVE-2024-56072

CVE-2024-56072

Description

An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of service (application crash) via a crafted packet that specifies many sFlow samples.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FastNetMon Community Edition ≤1.2.7 sFlow v5 plugin crashes on crafted packets with excessive samples, enabling remote DoS.

Vulnerability

The sFlow v5 plugin in FastNetMon Community Edition through version 1.2.7 lacks bounds checking on the number of samples in a packet. A remote attacker can send a crafted sFlow v5 packet specifying an excessive number of flow or counter samples, causing the application to crash due to memory allocation failure or other resource exhaustion. The vulnerability exists in the parse_sflow_v5_packet function and the process_sflow_flow_sample and process_sflow_counter_sample functions [1][2].

Exploitation

An attacker with network access to the FastNetMon instance can send a specially crafted sFlow v5 packet containing a large number of samples (e.g., via the datagram_samples_count field or the number of flow/counter records). No authentication is required. The packet triggers the vulnerable code path, leading to a crash [1][2].

Impact

Successful exploitation results in a denial of service (application crash) of the FastNetMon daemon, disrupting network monitoring capabilities. The crash is immediate upon processing the malicious packet [1][2].

Mitigation

The issue is fixed in commits [1] and [2] which introduce capping logic for the number of sFlow samples and records. Users should update to a version containing these fixes (post-1.2.7) or apply the patches manually. No workaround is documented; the vendor recommends upgrading [1][2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.