PT-2021-20059 · Unknown · Vernemq Mqtt Broker
Jonathan Knudsen
·
Published
2021-06-08
·
Updated
2021-06-21
·
CVE-2021-33176
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
VerneMQ MQTT Broker versions prior to 1.12.0
Description
The issue is related to a denial of service attack due to excessive memory consumption. This occurs when the message broker handles untrusted inputs, causing it to consume large amounts of memory. As a result, the application is terminated by the operating system.
Recommendations
For VerneMQ MQTT Broker versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider implementing input validation to restrict the handling of untrusted inputs.
Fix
Deserialization of Untrusted Data
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vernemq Mqtt Broker