Impact
An integer overflow exists in the Svc::FileDownlink::SendPartial component of the fprime framework. When a specially crafted input feeds a value that exceeds integer limits, the component can trigger a crash, interrupting its service loop and causing a denial of service. The weakness conforms to CWE‑400.
Affected Systems
The affected product is the fprime framework, version 4.2.2. No vendor level information is available beyond the framework name.
Risk and Exploitability
The CVSS score is 7.5, and the EPSS score is < 1%; the vulnerability is not listed in CISA KEV. Consequently the exploit likelihood appears low, but the impact—service interruption—remains significant. The description indicates that an attacker must supply a crafted input, likely via a network or local interface that exposes the SendPartial API. It is inferred that if this component is reachable, remote exploitation is possible, though no explicit attack path is given.
OpenCVE Enrichment