Impact
A flaw in the rt-claw Swarm RPC Receiver’s handle_rpc_request function allows incorrect authorization, enabling attackers to gain unauthorized access to RPC operations. The vulnerability can be exploited remotely, potentially allowing an attacker to perform privileged actions or disrupt services without proper authentication. The weakness is classified under CWE‑285 and CWE‑863, indicating a failure to enforce correct authorization controls.
Affected Systems
The affected product is Zevorn rt‑claw up to version 0.2.0, which contains the Swarm RPC Receiver component that uses the handle_rpc_request function in claw/services/swarm/swarm.c. The vulnerability exists in all releases before and including 0.2.0.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote access to the Receiver service, as the flaw permits manipulation over the network to bypass authorization checks.
OpenCVE Enrichment