Impact
The flaw is located in MySQL Server’s Pluggable Authentication component. When a high‑privileged attacker with network access engages the server through its multiple supported protocols, the defect can be triggered and cause resource exhaustion, resulting in a partial denial of service. No data loss, confidentiality breach or integrity compromise is described in the statement.
Affected Systems
Oracle Corporation’s MySQL Server versions 9.0.0 through 9.5.0 are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 2.7 shows a low‑to‑moderate impact limited to availability. The EPSS score of under 1% indicates the exploitation probability in the wild is very low. The vulnerability is not listed in the CISA KEV catalogue. The attack vector, inferred from the description, requires a high privileged attacker with network access via multiple protocols to trigger the denial of service event.
OpenCVE Enrichment