PT-2026-68487 · Sonic3Air · Sonic3Air
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sonic 3 A.I.R. versions prior to commit 2492d18
Description
A missing source address validation issue exists in the
ConnectionManager where established connections are resolved using only a two-byte local connection handle. The system fails to verify if the datagram source address matches the registered remote address for the connection. An on-path attacker capable of observing cleartext UDP traffic can inject arbitrary packets into established sessions by forging the two-byte connection identifier. This allows for session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without the need for IP address spoofing.Recommendations
Update Sonic 3 A.I.R. to commit 2492d18 or a later version.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonic3Air