CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2023-54394: PocketMine-MP 0 to before 4.18.0-ALPHA2

CVE-2023-54394. CVSS 3.1 base score 4.3 (MEDIUM, Vendor/CNA). EPSS 0.00379 (percentile 0.29613), scored 2026-10-06.

Affected technology

PocketMine-MP · 0 to before 4.18.0-ALPHA2
pmmp

Description’s affected range: before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low.

Published

CWE
CWE-770
CCR priority
17.3 /100 (P5)
CVSS 3.1
4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L · Vendor/CNA
EPSS
0.00379 · percentile 0.29726 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2023-54394.html