PT-2018-4703 · Eclipse · Mqtt

Peter Sorowka

+1

·

Publicado

2018-05-31

·

Atualizado

2019-10-09

·

CVE-2016-10523

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MQTT versions prior to 3.4.6 MQTT versions 4.0.x prior to 4.0.5
Description The issue allows specifically crafted MQTT packets to crash the application, making a denial of service attack feasible with very little bandwidth. This is achieved through specific sequences of MQTT packets.
Recommendations Update to version 3.4.6 or later for version 3.x. Update to version 4.0.5 or later for version 4.x.

Exploit

Correção

Buffer Overflow

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10523
GHSA-G3R2-65GC-QPQC

Produtos afetados

Mqtt