PT-2021-20059 · Unknown · Vernemq Mqtt Broker

Jonathan Knudsen

·

Published

2021-06-08

·

Updated

2021-06-21

·

CVE-2021-33176

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VerneMQ MQTT Broker versions prior to 1.12.0
Description The issue is related to a denial of service attack due to excessive memory consumption. This occurs when the message broker handles untrusted inputs, causing it to consume large amounts of memory. As a result, the application is terminated by the operating system.
Recommendations For VerneMQ MQTT Broker versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider implementing input validation to restrict the handling of untrusted inputs.

Fix

Deserialization of Untrusted Data

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33176

Affected Products

Vernemq Mqtt Broker