Impact
This vulnerability in PocketMine-MP allows attackers to submit banner NBT data that contains invalid dye color IDs during deserialization. The server does not validate these IDs and consequently triggers undefined offset errors that crash the server, causing a denial of service to all connected players.
Affected Systems
PocketMine-MP versions prior to 4.8.1 are affected. Users running pmmp: PocketMine-MP before 4.8.1 are vulnerable. No additional vendor or product information is provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. EPSS information is not available, so the exact likelihood of exploitation remains unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is remote, with attackers able to trigger the crash through player inventory transactions or server commands.
OpenCVE Enrichment