PT-2020-13729 · Mqtt · Mqtt
Published
2020-06-04
·
Updated
2020-06-10
·
CVE-2020-13849
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MQTT protocol version 3.1.1
Description
The issue allows remote attackers to cause a denial of service, resulting in the loss of the ability to establish new connections. This is demonstrated by SlowITe, which exploits the requirement for a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client.
Recommendations
For MQTT protocol version 3.1.1, consider implementing measures to prevent abuse of the Keep-Alive value, such as limiting the maximum Keep-Alive value that can be specified by clients or implementing rate limiting on new connections. As a temporary workaround, consider restricting the ability of clients to specify high Keep-Alive values until a more permanent solution is available.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mqtt