CVE-2022-3577609.08.2022, 20:15Azure Site Recovery Denial of Service VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.2 MEDIUMADJACENT_NETWORKLOWHIGHCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HmicrosoftCNA6.2 MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:CCVEADP------CISA-ADPADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 18%VendorProductVersionmicrosoftazure_site_recovery_vmware_to_azure𝑥< 9.50.6419.1𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35776https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35776