Impact
An unauthenticated attacker with network access can trigger the vulnerability in MySQL Cluster’s NDB Operator component, causing the cluster to hang or repeatedly crash, which results in a denial of service. The flaw also permits unauthorized updates, inserts, or deletes on data exposed through the cluster, thereby compromising data integrity. The weakness is a classic example of improper access control (CWE-284), reflected in the CVSS 3.1 base score of 8.2 that highlights integrity and availability impacts.
Affected Systems
The vulnerability affects Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. It resides in the Cluster: NDB Operator component and is reachable via multiple network protocols, without requiring authentication.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity issue. Although the EPSS score is less than 1 %, the lack of authentication and direct network reachability provide a strong incentive for attackers, and the potential to cause both service disruption and data tampering make this vulnerability a significant threat. The vulnerability is not listed in CISA’s KEV catalog, but its impact and easy exploitation path justify immediate attention.
OpenCVE Enrichment