Impact
A defect was discovered in Eleveo Quality Management version 9.7.0 that allows an attacker to manipulate the argument labels supplied to the /enc-fwk-data/api/v3/conversations/<ID>/events API endpoint. This manipulation causes the Conversation Handler component to enter an error state that can be repeated to exhaust resources, resulting in a denial of service. The flaw is classified as an Improper Resource Management issue (CWE‑404).
Affected Systems
Eleveo Quality Management 9.7.0 is the only version explicitly mentioned as vulnerable. No other versions or product variants were listed in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, yet a public exploit has been documented. The attack vector is remote, relying on HTTP requests to the vulnerable API endpoint. Because the flaw can be triggered without privileged access, anyone on the network or the internet (depending on exposure) can potentially disrupt the service.
OpenCVE Enrichment