4.4
CVE-2026-35901
- EPSS 0.25%
- Veröffentlicht 27.04.2026 00:00:00
- Zuletzt bearbeitet 05.05.2026 13:41:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the same media track within a single RTSP session. This causes the server to reset the RTSP connection, leading to a denial-of-service condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mercurycom ≫ Mipc252w Firmware Version1.0.5 Updatebuild_230306
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.157 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
https://github.com/izxnfirh8148/CVE_REQUESTS_references/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_2th/README.md