Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47078

Опубликовано: 25 сент. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
EPSS Низкий

Описание

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:meshtastic:meshtastic_firmware:*:*:*:*:*:*:*:*
Версия до 2.5.1 (исключая)

EPSS

Процентиль: 11%
0.00038
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-863

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 1 года назад

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.

EPSS

Процентиль: 11%
0.00038
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-863