PT-2024-27692 · Tuya · Tuya Sdk
Kaizheng
·
Published
2024-04-14
·
Updated
2024-08-01
·
CVE-2024-3764
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Tuya SDK versions up to 5.0.x
Description
A vulnerability has been found in the MQTT Packet Handler component, which can lead to denial of service. The attack can be launched remotely, but the vendor notes that a malicious actor would have to crack TLS first or use a legitimate login to initiate the attack. The real existence of this vulnerability is still doubted at the moment.
Recommendations
For Tuya SDK versions up to 5.0.x, upgrade to version 5.1.0 to address this issue.
As a temporary workaround, consider restricting access to the MQTT Packet Handler component until a patch is available.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuya Sdk