Impact
The vulnerability lies in how the Wazuh cluster protocol parser treats the packet header’s payload length field. In all versions from 3.9.0 up to, but excluding, 4.14.5, the length is accepted before authentication or decryption and is used directly to allocate memory, allowing an attacker to send a crafted header with an arbitrarily large length. This results in uncontrolled memory allocation and eventual exhaustion, causing the cluster service to become unresponsive – a remote, unauthenticated denial of service that does not affect confidentiality or integrity.
Affected Systems
The affected product is the Wazuh open‑source platform. All releases from 3.9.0 through 4.14.4 are vulnerable; earlier versions are unaffected, and versions 4.14.5 and later contain the fix. Systems running Wazuh in cluster mode on the default port are particularly at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1 percent suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it remotely by sending a payload over the cluster protocol without authentication, and no special privileges are required.
OpenCVE Enrichment