PT-2024-23737 · Nanomq · Nanomq

Dqp10515

·

Published

2024-04-17

·

Updated

2025-06-10

·

CVE-2024-31040

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NanoMQ version 0.21.7
Description The issue is related to a Buffer Overflow vulnerability in the get var integer function in mqtt parser.c. This allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.
Recommendations For NanoMQ version 0.21.7, consider disabling the get var integer function in mqtt parser.c as a temporary workaround until a patch is available. Restrict access to the mqtt parser.c module to minimize the risk of exploitation. Avoid using the vulnerable function until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-31040

Affected Products

Nanomq