Vulnerabilities
Vulnerable Software
Eclipse:  >> Mosquitto  >> 2.0.1  Security Vulnerabilities
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
CVSS Score
6.5
EPSS Score
0.004
Published
2021-07-22
In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.
CVSS Score
6.5
EPSS Score
0.006
Published
2021-04-07


Contact Us

Shodan ® - All rights reserved