Impact
The vulnerability is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that leads to a heap overflow, enabling an attacker to reliably crash the application. This weakness corresponds to CWE‑190. The impact is loss of service for the affected system, without evidence of code execution or data theft. Local or remote users who can initiate a TCPCLv3 handshake with the vulnerable software can trigger the DoS.
Affected Systems
The affected product is D3TN GmbH's µD3TN. Only version 0.15.0 is known to contain the flaw; the latest published update, 0.15.1, resolves the issue and higher versions are assumed safe.
Risk and Exploitability
The CVSS score of 7.5 indicates a high potential for disruption. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote network-based connection that initiates the TCPCLv3 handshake; this inference is drawn from the mention of a network‑level protocol and the nature of the affected component.
OpenCVE Enrichment