Impact
A remote, unauthenticated attacker can trigger a denial of service on the HPE IceWall Federation Agent and Proxy by abusing a weakness that permits arbitrary requests to overwhelm the service. The flaw is identified as CWE-241, indicating insufficient validation of input integrity. The resulting impact is service disruption for users relying on the affected component.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise HPE IceWall products, specifically the Federation Agent and Proxy components. No specific version information is provided, so any deployed instances of these components could be susceptible.
Risk and Exploitability
The CVSS score of 7.5 classifies this flaw as high severity, reflecting a significant risk of disruption. Although EPSS data is missing and the vulnerability is not listed in CISA KEV, the reported attack vector is remote and unauthenticated, inferred from the description. An attacker could potentially craft requests to exhaust resources and halt the service, pending the presence of the unpatched component.
OpenCVE Enrichment