Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2895

Опубликовано: 07 нояб. 2017
Источник: nvd
CVSS3: 8.2
CVSS3: 8.2
CVSS2: 6.4
EPSS Низкий

Описание

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cesanta:mongoose:6.8:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00376
Низкий

8.2 High

CVSS3

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 8 лет назад

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

CVSS3: 8.2
debian
около 8 лет назад

An exploitable arbitrary memory read vulnerability exists in the MQTT ...

CVSS3: 8.2
github
больше 3 лет назад

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

EPSS

Процентиль: 59%
0.00376
Низкий

8.2 High

CVSS3

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-125