PT-2021-20058 · Emq · Emq X Broker

Jonathan Knudsen

·

Published

2021-06-08

·

Updated

2021-06-16

·

CVE-2021-33175

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions EMQ X Broker versions prior to 4.2.8
Description The issue is related to the handling of untrusted inputs, which causes excessive memory consumption. This results in a denial of service attack, where the message broker consumes large amounts of memory, leading to the application being terminated by the operating system.
Recommendations For EMQ X Broker versions prior to 4.2.8, update to version 4.2.8 or later to resolve the issue. As a temporary workaround, consider restricting the handling of untrusted inputs to minimize the risk of excessive memory consumption.

Fix

Deserialization of Untrusted Data

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33175

Affected Products

Emq X Broker