PT-2021-7060 · Eclipse+3 · Eclipse Mosquitto+3
Bin Yuan
+5
·
Published
2021-08-09
·
Updated
2025-03-10
·
CVE-2021-41039
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Eclipse Mosquitto versions 1.6 through 2.0.11
Description
The issue is related to the implementation of the MQTT v5 protocol in Eclipse Mosquitto, which can cause excessive CPU usage. This can be exploited by a remote attacker to cause a denial of service. The problem occurs when an MQTT v5 client connects with a large number of
user-property properties.Recommendations
For Eclipse Mosquitto versions 1.6 through 2.0.11, consider restricting the number of
user-property properties that can be sent by an MQTT v5 client to prevent excessive CPU usage. As a temporary workaround, restrict access to the MQTT v5 protocol until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Eclipse Mosquitto
Linuxmint
Ubuntu