VYPR

Beats

by Elastic

Source repositories

CVEs (5)

  • CVE-2025-68382MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.

  • CVE-2025-68381MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.

  • CVE-2023-31421MedOct 26, 2023
    risk 0.38cvss 5.9epss 0.00

    It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the…

  • CVE-2023-49922MedDec 12, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or…

  • CVE-2025-68388MedDec 18, 2025
    risk 0.27cvss 5.3epss 0.00

    Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.