D19-0h6a1
CVSS:
4.0 (AV:N/AC:L/Au:S/C:P/I:N/A:N)
False Positive:
t
Variants:
2
Year:
2017
Description
This strike exploits an ACL bypass vulnerability in Mosquitto. If the username or client ID field is set to # or +, ACLs will be completely bypassed. An attacker can send a crafted mqtt message to access mqtt topics without proper ACL rights.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}