PT-2018-4703 · Eclipse · Mqtt

Peter Sorowka

+1

·

Published

2018-05-31

·

Updated

2019-10-09

·

CVE-2016-10523

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MQTT versions prior to 3.4.6 MQTT versions 4.0.x prior to 4.0.5
Description The issue allows specifically crafted MQTT packets to crash the application, making a denial of service attack feasible with very little bandwidth. This is achieved through specific sequences of MQTT packets.
Recommendations Update to version 3.4.6 or later for version 3.x. Update to version 4.0.5 or later for version 4.x.

Exploit

Fix

Buffer Overflow

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10523
GHSA-G3R2-65GC-QPQC

Affected Products

Mqtt