Impact
An authenticated attacker can exceed the session flow control incoming window in Apache Qpid Proton‑Dotnet, potentially leading to a denial of service condition. The flaw is a classic resource exhaustion weakness (CWE‑770). If exploited, the attacker can cause the server to become unresponsive or to consume excessive resources, affecting availability for legitimate users.
Affected Systems
The vulnerability is present in Apache Qpid Proton‑Dotnet version 1.0.0 and all earlier releases. The product is developed by the Apache Software Foundation.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The flaw requires authentication, limiting impact to systems where credentials are compromised or misconfigured. There is no evidence of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Even with a low EPSS score, remediation remains necessary, as the impact on availability can be severe for exposed configurations.
OpenCVE Enrichment