Impact
This vulnerability is an out-of-bounds read caused by improperDB C++ client. When the client receives malformed data from the server, it reads beyond allocated buffer boundaries and crashes. The primary impact is that rely on the client; the attacker does not gain code execution or data exfiltration capabilities based on the current description.
Affected Systems
Apache IoTDB C++ client versions prior to 1.3.8 and prior to 2.0.10 are affected. Specifically, all releases from 1.3.5 up to but not including 1.3.8 and from 2.0.5 up to but.10. Users should upgrade to version 2.0.10 or later to receive the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in CISA's KEV catalog. Based on the nature of the flaw, the likely attack vector is a malicious or compromised server that sends specially crafted TsBlock data to the client. An attacker can force the client process to terminate, disrupting client.
OpenCVE Enrichment