Vulnerability identifier: #VU33230
Vulnerability risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-400
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Eclipse Mosquitto
Server applications /
Other server solutions
Vendor: Eclipse
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Eclipse Mosquitto: 1.4.14
External links
http://bugs.eclipse.org/bugs/show_bug.cgi?id=529754
http://lists.debian.org/debian-lts-announce/2018/03/msg00037.html
http://lists.debian.org/debian-lts-announce/2018/06/msg00016.html
http://mosquitto.org/blog/2018/02/security-advisory-cve-2017-7651-cve-2017-7652/
http://www.debian.org/security/2018/dsa-4325
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.