PT-2024-21274 · Unknown · Mqtt Stack

Carlo Meijer

+1

·

Published

2024-03-12

·

Updated

2025-01-24

·

CVE-2024-26001

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The MQTT stack is susceptible to an unauthenticated remote attack due to improper input validation, allowing an attacker to write memory out of bounds. The brute force attack is not always successful because of memory randomization. An exploit for this issue may exist, with potential links to the exploit code available at https://t.co/iVuBGZrI6Y. Unfortunately, the specific versions of the MQTT stack affected are not mentioned in the provided text. #MQTT #cybersecurityawareness #cybersecurity #infosec #hacker #mqttstack #remotattack #memoryrandomization

Fix

Memory Corruption

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-26001
ZDI-24-862

Affected Products

Mqtt Stack