Impact
An authenticated attacker can send a disposition frame that specifies very large or illegal ranges, which the Proton-Dotnet runtime handles in a naive way that causes excessive CPU consumption. The result is a denial of service of the application or service using the library. The weakness is a deficient input validation (CWE-606).
Affected Systems
The vulnerability affects Apache Qpid Proton-Dotnet, with all releases through version 1.0.0 impacted. No newer versions before the fix are provided.
Risk and Exploitability
The risk is significant for services that rely on Proton-Dotnet for messaging, as any authenticated user can trigger the DoS. The exploitation requires the attacker to be authenticated within the system; therefore, it targets internal or compromised accounts. While the EPSS score is shown as < 1% and the issue is not listed in the CISA KEV catalog, the availability of a direct upgrade mitigates the threat. The severity, as quantified by a CVSS score of 6.5, indicates moderate risk given the potential for service interruption. Proactively applying the patch is the recommended approach to eliminate the vulnerability.
OpenCVE Enrichment