CVE-2018-18407: Broadcom Tcpreplay

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_checksum.h, causing a denial of service.

Affected products

Published 2018-10-17. Last modified 2026-06-17.