Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Felipe Balabanian

#37540de 56,333
7.5CVSS total
Vulnerabilidades · 1
PT-2018-8420
7.5
2018-04-24
Eclipse · Eclipse Mosquitto · CVE-2017-7651
**Name of the Vulnerable Software and Affected Versions** Eclipse Mosquitto version 1.4.14 **Description** The issue allows a user to shut down the Mosquitto server by filling the RAM memory with numerous connections that have large payloads. This can be achieved without authentication during the connection phase of the MQTT protocol. **Recommendations** For Eclipse Mosquitto version 1.4.14, consider restricting the number of connections or limiting the payload size to prevent excessive memory usage until a patch is available. As a temporary workaround, implement authentication for the connection phase to minimize the risk of exploitation.