Описание
In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
EPSS
Процентиль: 20%
0.00274
Низкий
7.7 High
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 7.7
github
3 месяца назад
In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at per-device scope.
EPSS
Процентиль: 20%
0.00274
Низкий
7.7 High
CVSS3
Дефекты
CWE-639