CISA Malcolm
Summary
The CISA Malcolm network traffic analysis tool suite has several vulnerabilities that could allow an attacker to cause a denial-of-service condition or execute arbitrary code. These issues stem from unmanaged resource allocation during archive extraction, path traversal, unrestricted file uploads, incorrect authorization, and improper handling of highly compressed data.
IFF Assessment
Multiple critical vulnerabilities in a widely used network analysis tool create significant risks for defenders.
Severity
Defender Context
Defenders should be aware of these vulnerabilities in CISA Malcolm, a critical infrastructure sector tool. Prompt patching or mitigation is crucial to prevent denial-of-service attacks or code execution, which could disrupt network monitoring and analysis capabilities.