Kea
ISC- Product type
- Other
- Catalog vulnerabilities
- 11
Severity across 9 analyzed records
Verify to analyze this security profile
en
As of 09/13/2026, within CyStack's analyzed data, Kea has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Kea and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-3608Stack overflow in Kea daemons | Exploitation statusNot known exploited | FixYes | Published03/25/2026 | SeverityHigh |
CVE-2025-11232Invalid characters cause assert | Exploitation statusNot known exploited | FixYes | Published10/29/2025 | SeverityHigh |
CVE-2025-40779Kea crash upon interaction between specific client options and subnet selection | Exploitation statusNot known exploited | FixYes | Published08/27/2025 | SeverityHigh |
CVE-2025-32803Insecure file permissions can result in confidential information leakage | Exploitation statusNot known exploited | FixYes | Published05/28/2025 | SeverityMedium |
CVE-2025-32802Insecure handling of file paths allows multiple local attacks | Exploitation statusNot known exploited | FixYes | Published05/28/2025 | SeverityMedium |
CVE-2025-32801Loading a malicious hook library can lead to local privilege escalation | Exploitation statusNot known exploited | FixYes | Published05/28/2025 | SeverityHigh |
CVE-2019-6474A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | Exploitation statusNot confirmed | FixYes | Published10/16/2019 | SeverityMedium |
CVE-2019-6473A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | Exploitation statusNot confirmed | FixYes | Published10/16/2019 | SeverityMedium |
CVE-2019-6472A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | Exploitation statusNot confirmed | FixYes | Published10/16/2019 | SeverityMedium |
CVE-2018-5739Failure to release memory may exhaust system resources | Exploitation statusNot confirmed | FixYes | Published01/16/2019 | SeverityMedium |
CVE-2015-8373 | Exploitation statusNot confirmed | FixNot confirmed | Published12/22/2015 | SeverityUnknown |