Impact
A vulnerability in the SetPassword API allows any authenticated Velociraptor user, even those with only a readerrole, to terminate the entire server process by sending a request with a non‑existent username. The flaw stems from a null pointer dereference and a logical condition error, causing the server to crash and interrupt all Velociraptor services. This results in a denial of service rather than data compromise or remote code execution.
Affected Systems
Rapid7 Velociraptor is affected. No specific version numbers are listed in the CNA data, so all supported releases may carry the issue until the vendor issues a fix.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the exploit requires authenticated access to the API, the threat is limited to users with API credentials; nevertheless, an internal attacker or compromised user can bring the service down. EPSS information is not available, and the vulnerability is not listed in CISA KEV, implying no known mass exploitation yet. The primary risk is service disruption if the vulnerability is leveraged by an insider or a credential‑stolen account.
OpenCVE Enrichment