Impact
An unauthenticated user with network access to the Ops Manager web port can repeatedly call monitoring endpoints that perform expensive work without any rate limiting. The resulting uncontrolled resource consumption can temporarily degrade the responsiveness of other traffic handled by the same process. This flaw matches the Uncontrolled Resource Consumption weakness (CWE‑770) and does not directly compromise confidentiality or integrity but can impair availability for legitimate users.
Affected Systems
MongoDB Ops Manager is affected. All currently deployed instances that expose the web monitoring endpoints are susceptible; specific version information was not supplied.
Risk and Exploitability
Given the CVSS score of 6.9, the vulnerability represents moderate severity. The EPSS score is not available, and it is not included in the CISA KEV list, but the fact that the attack requires only unauthenticated network access to the Ops Manager web port means that attackers can exploit it remotely. The lack of authentication combined with no rate limiting increases the likelihood that repeated requests could be launched by an attacker, likely resulting in degraded service performance or temporary denial of service.
OpenCVE Enrichment