Impact
Consul Community Edition and Consul Enterprise versions 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service that can be triggered by writing a malicious service-router configuration entry. The flaw allows an authorized user with config‑entry write permission to cause an agent to exit unexpectedly, effectively crashing the Consul server. The vulnerability is limited to configurations that perform an Enterprise‑to‑Community Edition downgrade, and requires valid authentication and write access to configuration entries. The impact is localized to availability; confidentiality and integrity are not directly compromised.
Affected Systems
HashiCorp Consul Community Edition versions 1.18.0 to 2.0.2 and HashiCorp Consul Enterprise versions 1.18.0 through 2.0.2 (pre‑2.0.3). The vulnerable path exists for all these releases. The advisory explicitly lists the affected product families and the ranges that contain the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, meaning no publicly known exploitation probability is provided, but the weakness involves a drop‑in agent crash that is straightforward to trigger once the necessary permission is held. The issue is not yet in the CISA KEV catalog, suggesting it has not been widely abused yet. The most likely attack vector is an internal attacker or compromised service account with config‑entry write rights attempting to disrupt service availability by inserting a harmful configuration entry.
OpenCVE Enrichment