Impact
This vulnerability is a null pointer dereference in the mk_sched_event_close function within the Monkey server code. A malicious actor can send a specially crafted HTTP request that triggers the dereference, leading to an application crash and the inability to serve legitimate traffic. The failure is localized to the Monkey process and results in service disruption but does not affect wider system confidentiality or integrity.
Affected Systems
The affected software is the Monkey server. No specific vendor or product list is provided in the CNA data. Version information is unknown, but the flaw exists in code preceding commit 4fb0c16. Operators should verify the installed Monkey version and review code commits for this issue.
Risk and Exploitability
The exploit is possible when an attacker can reach the Monkey HTTP endpoint, which is a remote network-based attack vector. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the fault can still be readily triggered by an attacker with network access, leading to a high impact denial of service that could affect availability of dependent services. The CVSS score of 7.5 indicates high severity.
OpenCVE Enrichment