APIs Lack Rate Limiting
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In short
The Azure Access Technology BLU-IC2 and BLU-IC4 devices don't limit how many requests an attacker can send to their APIs, allowing someone to flood them with traffic and make them unavailable.
Technical detail
CWE-770 vulnerability in Azure Access Technology BLU-IC2 and BLU-IC4 (versions up to 1.19.5) lack rate limiting on APIs, enabling resource exhaustion attacks via uncontrolled request flooding with no authentication or prior access required, resulting in denial of service.
Summary generated and translated by AI from the official description.
Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H