Impact
The OpenRGB network protocol permits an attacker to send malformed or misleading data that leads to memory exhaustion and out‑of‑bounds memory reads and writes. This flaw can cause the OpenRGB service to become unresponsive and potentially expose sensitive memory contents. The weakness is classified as Improper Input Handling.
Affected Systems
The vulnerable component is OpenRGB developed by CalcProgrammer1. No specific version numbers are listed in the CVE entry; any installation of OpenRGB that uses the network protocol exposed in this vulnerability is potentially affected.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity. The EPSS score is not available, but the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit it remotely by targeting the OpenRGB protocol from an external network or a compromised device. Based on the description, the likely attack vector is a remote network service exploitation.
OpenCVE Enrichment