PT-2018-8420 · Eclipse+1 · Eclipse Mosquitto+1
Felipe Balabanian
·
Published
2018-04-24
·
Updated
2019-10-09
·
CVE-2017-7651
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Mosquitto version 1.4.14
Description
The issue allows a user to shut down the Mosquitto server by filling the RAM memory with numerous connections that have large payloads. This can be achieved without authentication during the connection phase of the MQTT protocol.
Recommendations
For Eclipse Mosquitto version 1.4.14, consider restricting the number of connections or limiting the payload size to prevent excessive memory usage until a patch is available. As a temporary workaround, implement authentication for the connection phase to minimize the risk of exploitation.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Eclipse Mosquitto