Impact
The vulnerability exists in MISP versions earlier, where two API authentication failure paths bypass the existing throttling mechanism. As a result, each failed authentication attempt that carries either no API key or an entry to the Log model without any rate limit. The infinite log generation can consume disk space or database resources denial of service. This represents an input validation weakness (CWE‐400) and a memory exhaustion flaw (CWE‐770).
Affected Systems
Affected systems are deployments of the MISP open‑source platform with a version of 2.5.45 or older. The affected vendor and product are MISP: MISP. No additional sub‑versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is readily exploitable via the public API endpoints: requests with either no API key or a key of incorrect length from any IP address, creating a log entry each time. Because the attacker controls the source IP, the throttle key is also controllable, allowing the attacker to bypass any per‑IP limits until the fix is applied. This could exhaust disk or database capacity and cause a denial of service.
OpenCVE Enrichment