CVE-2025-48392

7.5

Apache Software Foundation · IoTDB

Apache IoTDB versions 1.3.3 through 1.3.4 and 2.0.1-beta through 2.0.4 are susceptible to a denial of service vulnerability.

Executive summary

A denial of service vulnerability in Apache IoTDB allows unauthenticated remote attackers to disrupt system availability.

Vulnerability

This is a denial of service (DoS) vulnerability that can be triggered by an unauthenticated remote attacker. The weakness allows for the disruption of service availability, preventing legitimate users from accessing the IoTDB platform.

Business impact

The exploitation of this vulnerability results in the denial of service for the affected IoTDB instance, which can cause significant operational downtime. Given the CVSS score of 7.5, this high severity flaw poses a substantial risk to business continuity, especially in environments where IoT data ingestion and management are mission critical.

Remediation

Immediate Action: Upgrade your Apache IoTDB installation to version 2.0.5 or later to resolve this vulnerability.

Proactive Monitoring: Monitor system logs for unusual spikes in resource consumption or sudden service crashes that may indicate an active denial of service attempt.

Compensating Controls: Implement network access controls to restrict access to the IoTDB management interface to trusted IP ranges, which limits the attack surface for unauthenticated actors.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability is high due to its potential to impact system availability. Administrators should prioritize upgrading to version 2.0.5 immediately to eliminate the risk of service disruption. Ensure that all deployment environments are updated and that access control policies are reviewed to maintain a secure perimeter.

More Apache Software Foundation CVEs

Sources

Originally found and disclosed by yyjLF, per the CVE Program record.