Vulnerabilities
Vulnerable Software
Chirpstack:  Security Vulnerabilities
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-03-21
An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malformed frequency attributes in CollectAndCallOnceCollect in internal/uplink/collect.go. NOTE: the vendor's position is that there are no "guarantees that allowing untrusted LoRa gateways to the network should still result in a secure network.
CVSS Score
6.5
EPSS Score
0.005
Published
2020-11-09


Contact Us

Shodan ® - All rights reserved