← Vulnerability feed

Vulnerability record · CVE-2025-9384 · published 24 August 2025

CVE-2025-9384: Broadcom tcpreplay improper resource shutdown vulnerability

Broadcom · Tcpreplay

A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrading the affected component is advised. The vendor explains, that he was "[a]ble to reproduce in 6fcbf03 but not in 4.5.2-beta2".

1.9 CVSS 4.0 Low EPSS 0.25% · top 85.4% CWE-404 · Improper resource shutdownCWE-476 · NULL pointer dereference
1.9CVSS 4.0 base score, v2 1.7
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrading the affected component is advised. The vendor explains, that he was "[a]ble to reproduce in 6fcbf03 but not in 4.5.2-beta2".

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-9384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18408Broadcom tcpreplay use after free vulnerabilityA use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c…EPSS 2.3%9.1CVE-2020-12740Broadcom tcpreplay out-of-bounds read vulnerabilitytcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ip…EPSS 1.7%7.8CVE-2025-51006Broadcom tcpreplay double free vulnerabilityWithin tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linux…EPSS 0.19%7.8CVE-2024-3024Broadcom tcpreplay heap-based buffer overflow vulnerabilityA vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the fil…EPSS 0.44%7.8CVE-2022-37049Broadcom tcpreplay out-of-bounds write vulnerabilityThe component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is dif…EPSS 0.42%7.8CVE-2022-37047Broadcom tcpreplay out-of-bounds write vulnerabilityThe component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this …EPSS 0.42%7.8CVE-2022-37048Broadcom tcpreplay out-of-bounds write vulnerabilityThe component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: …EPSS 0.42%7.8CVE-2022-27418Broadcom tcpreplay out-of-bounds write vulnerabilityTcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c.EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2025-9384), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.