CVE-2025-46354
7.5Bloomberg · Comdb2
Bloomberg Comdb2 8.1 is vulnerable to a denial of service attack via a specially crafted network packet sent to the Distributed Transaction Commit/Abort functionality.
Executive summary
A critical denial of service vulnerability in Bloomberg Comdb2 8.1 allows unauthenticated attackers to crash the service via malicious network packets.
Vulnerability
This vulnerability is a reachable assertion (CWE-617) within the Distributed Transaction Commit/Abort Operation functionality, which can be triggered by an unauthenticated attacker sending a specially crafted network packet.
Business impact
The ability for an unauthenticated remote attacker to trigger a denial of service condition poses a significant threat to business continuity and service availability. With a CVSS score of 7.5, this high-severity flaw could lead to critical system outages, disrupting distributed transaction processing and impacting downstream business operations that rely on the Comdb2 database.
Remediation
Immediate Action: Consult official Bloomberg security advisories and the Talos Intelligence report (TALOS-2025-2198) for available vendor patches or configuration updates.
Proactive Monitoring: Monitor network traffic for unusual or malformed packet patterns directed at the Comdb2 service ports and review system logs for assertion errors or unexpected service crashes.
Compensating Controls: Deploy a network-level firewall or intrusion prevention system to filter and inspect incoming traffic to the Comdb2 service, specifically blocking malformed packets that match the attack vector.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated service disruption, administrators should treat this vulnerability with high priority. Users of Bloomberg Comdb2 8.1 should verify their exposure and apply any provided vendor patches immediately to prevent potential service degradation or outages.
Sources
Originally found and disclosed by Discovered by a member of Cisco Talos., per the CVE Program record.