CVE-2019-6473: Ics Kea

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

Affected products

  • Ics Kea: from 1.4.0, up to and including 1.5.0; version 1.6.0 only

Published 2019-10-16. Last modified 2026-06-17.