CVE-2013-0005 describes a denial-of-service vulnerability in the WCF Replace function of the Open Data (OData) protocol within Microsoft .NET Framework versions 3.5 and 4, as well as the Management OData IIS Extension on Windows Server 2012. This flaw allows remote, unauthenticated attackers to trigger resource consumption and daemon restarts through specially crafted HTTP requests. With a CVSS score of 7.8 (High), this vulnerability poses a significant risk of service disruption, requiring no authentication or complex attack methods. While it has a high FAUCET Risk Score of 98/100, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:management_odata_iis_extension:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.