Impact
PocketMine-MP versions prior to 5.43.1 allow an attacker to trigger a server crash by taking advantage of an uninitialized property that occurs when the Certificate field is not properly validated during offline login authentication. The flaw results in an uninitialized property access error that brings the server down, causing a denial of service. The nature of the weakness is an improper input validation that leads to code failure, classified under CWE-184.
Affected Systems
The affected product is PocketMine-MP from pmmp, specifically all releases before version 5.43.1. Users running those earlier builds are susceptible to the crash whenever an unauthenticated player logs in.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. Although an EPSS score is not available, the lack of a listed KEV suggests this flaw is not currently exploited on a large scale. The likely attack vector is local or external, requiring an unauthenticated player to initiate an offline login; thus any player who can reach the server can trigger the crash, making this a viable denial of service vector if the server is exposed to untrusted networks.
OpenCVE Enrichment