Impact
PocketMine‑MP versions prior to 4.2.3 fail to validate damage metadata values that clients embed in the NBT data of tools and armor. Attackers can send negative or out‑of‑range damage values in an item stack, which triggers an unhandled exception inside the Durable class, causing the server process to terminate and leading to a service interruption for all connected players.
Affected Systems
The vulnerability affects PocketMine‑MP versions before 4.2.3. The affected product is the PocketMine‑MP server software, as identified by the CNA vendor pmmp.
Risk and Exploitability
The CVSS score is 7.1, reflecting a high severity level. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain. Based on the description, it is inferred that an attacker can trigger this by sending specially crafted NBT data from any client that can connect to the server. When such data is processed, the server will crash, constituting a Denial of Service that can be initiated remotely via a malformed packet.
OpenCVE Enrichment