CVE-2020-13849

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/06/2020
Last modified:
10/06/2020

Description

The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mqtt:mqtt:3.1.1:*:*:*:*:*:*:*