CVE-2017-7651
HIGH 7.5EPSS 5.2%
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 5.21% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2018-04-24
- Updated
- 2024-08-05
Proof-of-concept exploits (3)
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=529754
- St3v3nsS/CVE-2017-76511★ · 2022-02-21
- mukkul007/MqttAttack0★ · 2021-09-24