Impact
The vulnerability allows an unauthenticated attacker with network access to a MySQL Connector/C++ instance to repeatedly trigger a hang or crash, effectively denying service. It is identified as CWE-400 and results in a high availability impact, but it does not provide confidentiality or integrity compromise. Successful exploitation allows the attacker to make the connector become unresponsive.
Affected Systems
Oracle MySQL Connectors, specifically the Connector/C++ component versions 9.7.0 through 9.7.1 released by Oracle Corporation.
Risk and Exploitability
The base CVSS score of 7.5 indicates a high severity availability risk. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is network-based, requiring no authentication, meaning any host that can reach the connector over supported protocols can attempt the denial of service.
OpenCVE Enrichment