PT-2017-11602 · Mqtt · Mqtt.Js

Bintatsu Noda

+2

·

Published

2017-12-27

·

Updated

2019-10-03

·

CVE-2017-10910

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MQTT.js versions prior to 2.15.0
Description The issue lies in the handling of PUBLISH tickets, which may lead to an attacker causing a denial-of-service condition. This occurs because affected versions of mqtt do not properly handle PUBLISH packets returning from the server. However, if the only connected servers are trusted and guaranteed not to be under the control of a malicious actor, the vulnerability is completely mitigated.
Recommendations Update to version 2.15.0 or later. As a temporary workaround, consider restricting access to untrusted MQTT servers to minimize the risk of exploitation.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10910
GHSA-H9MJ-FGHC-664W

Affected Products

Mqtt.Js