Impact
The vulnerability allows an attacker to allocate resources without limits or throttling in ASP.NET Core, causing unbounded consumption of server resources and resulting in denial of service. This flaw can be triggered by unauthorized network traffic, preventing legitimate users from accessing the affected service.
Affected Systems
The affected product is Microsoft ASP.NET Core OData. No specific version ranges are provided in the advisory; organizations using this component should verify if they are affected by consulting the Microsoft Security Response Center or the update guide.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity. Because the exploit path requires only network access and no authentication, an unauthenticated attacker can initiate the resource exhaustion loop. While EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, the potential impact of crippling an entire application remains significant, warranting prompt remediation.
OpenCVE Enrichment