CVE-2025-36520
7.5Bloomberg · Comdb2
A null pointer dereference in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1 allows remote unauthenticated attackers to cause a denial of service via crafted packets.
Executive summary
A null pointer dereference vulnerability in Bloomberg Comdb2 8.1 allows unauthenticated remote attackers to crash the service, resulting in a denial of service.
Vulnerability
This is a null pointer dereference vulnerability (CWE-476) within the net_connectmsg Protocol Buffer Message processing logic. The vulnerability is exploitable by an unauthenticated attacker who sends specially crafted network packets to the target system.
Business impact
The successful exploitation of this vulnerability leads to a denial of service, which can cause significant operational disruption by rendering the database service unavailable. With a CVSS score of 7.5, this high severity flaw poses a substantial risk to business continuity, as it allows any remote attacker to crash critical infrastructure without requiring prior authentication or user interaction.
Remediation
Immediate Action: Monitor official communication channels from Bloomberg for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Implement network traffic monitoring to detect anomalous spikes in Protocol Buffer Message traffic directed at Comdb2 instances, which may indicate exploitation attempts.
Compensating Controls: Deploy network-level access controls or a firewall to restrict access to the Comdb2 service to known, trusted IP addresses, thereby reducing the attack surface for unauthenticated remote requests.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability and its potential to disrupt critical database operations, organizations should prioritize isolating affected Comdb2 instances from untrusted networks. Administrators must remain vigilant for vendor-supplied patches and treat this flaw with urgency due to the ease of exploitation by remote, unauthenticated actors.
Sources
Originally found and disclosed by Discovered by a member of Cisco Talos., per the CVE Program record.