Impact
The vulnerability exists in the Replication component of MySQL Server and MySQL Cluster. It allows a high‑privileged attacker with network access via multiple protocols to cause the database process to hang or repeatedly crash, resulting in a complete denial of service. This weakness is reflected in a CVSS v3.1 base score of 4.4 that targets availability only, with no impact on confidentiality or integrity, and is associated with the following CWEs: CWE-284, CWE-770.
Affected Systems
Affected products are Oracle MySQL Server and MySQL Cluster in the version ranges 8.4.0 through 8.4.10, 9.7.0 through 9.7.1, and for the cluster component 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1, as identified by Oracle.
Risk and Exploitability
The exploitability score is very low (EPSS < 1%) and the vulnerability is not yet listed in the CISA KEV catalog. The CVSS v3.1 base score of 4.4 indicates a moderate impact limited to availability, with a vector of AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H. An attacker who can connect to the database over the network and possesses the necessary high‑privileged credentials could trigger a crash via replication operations. No other prerequisites are noted, but the attack likely requires network access through multiple protocols.
OpenCVE Enrichment