Impact
A logic error in the middleware used by Wazuh causes the /events endpoint to ignore the configured global rate limit when the endpoint‑specific counter has not been exceeded. This allows an attacker to inject events into analysisd beyond the administrator‑defined limit, potentially overwhelming the system and degrading detection capability. The flaw is a typical denial‑of‑service or unauthorized injection vulnerability (CWE‑799).
Affected Systems
The issue affects Wazuh deployments running version 4.6.0 up to, but not including, 4.14.5. Administrators should verify that their installations are within this range before applying a patch.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw arises from an endpoint that accepts network requests, the most likely attack vector is remote HTTP traffic; an attacker would need to send repeated /events requests that trigger the rate‑limit bypass.
OpenCVE Enrichment