Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2020-13849

Disclosure Date: June 04, 2020 (last updated November 28, 2024)
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
Attacker Value
Unknown

CVE-2019-5432

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.
Attacker Value
Unknown

CVE-2016-10523

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS attack feasible with very little bandwidth.
0
Attacker Value
Unknown

CVE-2017-10910

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.
0