PT-2017-11602 · Mqtt · Mqtt.Js
Bintatsu Noda
+2
·
Published
2017-12-27
·
Updated
2019-10-03
·
CVE-2017-10910
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MQTT.js versions prior to 2.15.0
Description
The issue lies in the handling of PUBLISH tickets, which may lead to an attacker causing a denial-of-service condition. This occurs because affected versions of
mqtt do not properly handle PUBLISH packets returning from the server. However, if the only connected servers are trusted and guaranteed not to be under the control of a malicious actor, the vulnerability is completely mitigated.Recommendations
Update to version 2.15.0 or later. As a temporary workaround, consider restricting access to untrusted MQTT servers to minimize the risk of exploitation.
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mqtt.Js