Impact
The vulnerability in PocketMine‑MP before version 4.12.3 allows an attacker to create unauthenticated sessions that are not limited in number. By repeatedly connecting without sending a LoginPacket, the attacker can fill the server’s max‑player slot capacity. The result is a denial of service that prevents legitimate players from joining. This is an instance of excessive resource consumption, corresponding to CWE‑770.
Affected Systems
The affected product is PocketMine‑MP from pmmp. All releases before 4.12.3 are vulnerable; users running any of those versions should consider upgrading. No other vendors are mentioned.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity denial of service that can be exploited remotely by any network host that can reach the server. The EPSS score is not available, so the current exploitation probability is unclear, but the lack of authentication and the ability to consume all player slots suggest a straightforward attack path. The vulnerability is not listed in CISA’s KEV catalog, yet it can still impact services in environments where player availability is critical.
OpenCVE Enrichment