Impact
In ASP.NET Core, the OData libraries allocate resources without limits or throttling, enabling an attacker who can send requests over a network to a vulnerable OData endpoint to exhaust server resources and render the application unavailable. The weakness is uncontrolled resource consumption, classified as CWE-770.
Affected Systems
The affected products are Microsoft ASP.NET OData and Microsoft ASP.NET Core OData. No specific version information is available, so any version that has not yet applied the latest security update might be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be network-based; an unauthorized attacker would send a large number or prolonged OData requests to overwhelm resources.
OpenCVE Enrichment