Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Masataka Sakaguchi

Pesquisador deFujitsu Laboratories Ltd.
#43314de 56,334
6.5CVSS total
Vulnerabilidades · 1
PT-2017-11602
6.5
2017-12-27
Mqtt · Mqtt.Js · CVE-2017-10910
**Name of the Vulnerable Software and Affected Versions** MQTT.js versions prior to 2.15.0 **Description** The issue lies in the handling of PUBLISH tickets, which may lead to an attacker causing a denial-of-service condition. This occurs because affected versions of `mqtt` do not properly handle PUBLISH packets returning from the server. However, if the only connected servers are trusted and guaranteed not to be under the control of a malicious actor, the vulnerability is completely mitigated. **Recommendations** Update to version 2.15.0 or later. As a temporary workaround, consider restricting access to untrusted MQTT servers to minimize the risk of exploitation.