Impact
The vulnerability allows an attacker to manipulate the symbol value caching mechanism in Apache Qpid Proton-Dotnet before any authentication occurs. By causing the cache to grow without bounds, an attacker can exhaust memory or other resources, resulting in a denial of service. This flaw does not provide an attacker with confidential or integrity access; its primary consequence is availability disruption.
Affected Systems
Apache Qpid Proton-Dotnet releases up to and including version 1.0.0 are affected. Versions 1.1.0 and later contain the fix.
Risk and Exploitability
The attack can be performed from any external source that can send messages to the Proton‑Dotnet server, and no authentication is required. The description indicates that pre‑authentication resource exhaustion can be triggered, so it is inferred that the exploitability is high. Based on the information provided, there is no mention of real‑world exploitation, and this absence is inferred as the lack of evidence. Since the vulnerability is not listed in CISA KEV, the immediate threat level is considered moderate, but the potential for widespread service outages means administrators should treat it as high priority. The EPSS score is <1%, indicating a very low probability of exploitation at this time. The CVSS score of 7.5 indicates high severity.
OpenCVE Enrichment