CVE-2021-34431
CVE-2021-34431
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 1.1%KEV nãoPoC —Patch —
Ciclo de vida
22 jul 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
Productos afectados
The Eclipse Foundation · Eclipse Mosquitto¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →