Impact
The flaw is an improper control of interaction frequency with the email service, classified as CWE-799. An attacker with valid credentials can trigger the service to become unresponsive, effectively causing a denial of service that disrupts email communications. The vulnerability does not expose data or allow privilege escalation; it solely impacts the availability of the email feature. Based on the description, it is inferred that repeated email requests are likely used to exploit this flaw.
Affected Systems
IBM TS4300 tape library devices running firmware versions 1.1.0.1 through 1.7.1.1 are susceptible. Modern releases beginning with 1.7.2.0 contain the patch.
Risk and Exploitability
With a CVSS score of 4.3 the severity is moderate. The EPSS score of 0.26% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. Exploitation requires an authenticated session; the likely attack vector involves repeatedly sending email requests to deplete system resources, inferred from the description. The threat is primarily internal or from compromised credentials.
OpenCVE Enrichment