CVE-2025-48392
7.5Apache Software Foundation · IoTDB
Apache IoTDB versions 1.3.3 through 1.3.4 and 2.0.1-beta through 2.0.4 are susceptible to a denial of service vulnerability.
Executive summary
A denial of service vulnerability in Apache IoTDB allows unauthenticated remote attackers to disrupt system availability.
Vulnerability
This is a denial of service (DoS) vulnerability that can be triggered by an unauthenticated remote attacker. The weakness allows for the disruption of service availability, preventing legitimate users from accessing the IoTDB platform.
Business impact
The exploitation of this vulnerability results in the denial of service for the affected IoTDB instance, which can cause significant operational downtime. Given the CVSS score of 7.5, this high severity flaw poses a substantial risk to business continuity, especially in environments where IoT data ingestion and management are mission critical.
Remediation
Immediate Action: Upgrade your Apache IoTDB installation to version 2.0.5 or later to resolve this vulnerability.
Proactive Monitoring: Monitor system logs for unusual spikes in resource consumption or sudden service crashes that may indicate an active denial of service attempt.
Compensating Controls: Implement network access controls to restrict access to the IoTDB management interface to trusted IP ranges, which limits the attack surface for unauthenticated actors.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability is high due to its potential to impact system availability. Administrators should prioritize upgrading to version 2.0.5 immediately to eliminate the risk of service disruption. Ensure that all deployment environments are updated and that access control policies are reviewed to maintain a secure perimeter.
More Apache Software Foundation CVEs
Sources
Originally found and disclosed by yyjLF, per the CVE Program record.