Impact
An out‑of‑bounds read occurs in the SCRAM authentication response parsing routine of the MongoDB C Driver when it processes a malformed server‑final message. The driver attempts to read one byte past the end of a fixed‑size buffer; this byte is not returned through the protocol but can trigger a crash in the application, causing a denial of service. The weakness is classified as CWE‑125.
Affected Systems
Any application that uses the MongoDB C Driver and relies on SCRAM authentication is potentially affected. Specific driver versions are not listed in the advisory, so all releases prior to a fixed version are likely vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploits are documented. The attack vector is inferred to be a malicious server or network intermediary that can send a crafted SCRAM response before the server’s signature is verified, leading to the out‑of‑bounds read and application termination.
OpenCVE Enrichment