PT-2024-23088 · Chirpstack+1 · Chirpstack Chirpstack-Mqtt-Forwarder+2

Published

2024-03-21

·

Updated

2025-06-17

·

CVE-2024-29862

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ChirpStack chirpstack-mqtt-forwarder versions 4.2.0 and earlier ChirpStack chirpstack-gateway-bridge versions 4.0.10 and earlier
Description The Kerlink firewall in ChirpStack wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state. This issue affects the chirpstack-mqtt-forwarder and chirpstack-gateway-bridge components.
Recommendations For ChirpStack chirpstack-mqtt-forwarder versions 4.2.0 and earlier, update to version 4.2.1 or later. For ChirpStack chirpstack-gateway-bridge versions 4.0.10 and earlier, update to version 4.0.11 or later.

Fix

Related Identifiers

CVE-2024-29862

Affected Products

Chirpstack Chirpstack-Gateway-Bridge
Chirpstack Chirpstack-Mqtt-Forwarder
Kerlink Firewall