Impact
A malicious or man‑in‑the‑middle enrollment manager can send a malformed key response with fewer than four space‑separated fields, causing a NULL pointer dereference in the agent’s enrollment routine. This results in the agent process terminating, effectively denying service to the protected endpoint. The weakness is a classic null dereference (CWE-476).
Affected Systems
The vulnerability affects the Wazuh open‑source security platform, specifically agent versions 4.0.0 through 4.14.6. An attacker can exploit any agent that enrolls from an unverified manager lacking a CA certificate.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires control over or interception of the enrollment manager, typically over the network. Because the agent crashes deterministically when receiving the malformed response, a targeted denial of service can be achieved without privilege escalation.
OpenCVE Enrichment