Impact
The Pizzy Library lacks proper control of interaction frequency, allowing attackers to flood the system and exhaust resources. This Improper Control of Interaction Frequency flaw (CWE‑799) can lead to a denial of service, impacting availability of any services that rely on the library. The vulnerability is expressed as an ability to send a high volume of calls without restriction, potentially overwhelming memory and CPU on the host.
Affected Systems
MIA Technology Inc. Pizzy Library is affected in all releases from version 1.0.0.26250 up to but not including 1.3.9.26250. Any deployment using a version in this range is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the likely attack vector is that an attacker sends a large number of requests to a component that uses the library, causing resource exhaustion. Exploitation does not require elevated privileges; it merely requires the ability to invoke the library frequently.
OpenCVE Enrichment