« Volver al listado

CVE-2021-34431

Estado: ModificadaMedia (6.5)—

In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-34431",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "emo@eclipse.org",
      "affectedData": [
        {
          "vendor": "The Eclipse Foundation",
          "product": "Eclipse Mosquitto",
          "versions": [
            {
              "status": "affected",
              "version": "1.6",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.0.10"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-22T14:15:08.050",
  "references": [
    {
      "url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=573191",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=573191",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "emo@eclipse.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker."
    },
    {
      "lang": "es",
      "value": "En Eclipse Mosquitto versiones 1.6 hasta 2.0.10, si un cliente autenticado que se había conectado con MQTT versión v5 enviaba un mensaje CONNECT diseñado al broker, ocurriría una pérdida de memoria, que podría ser usada para proporcionar un ataque DoS contra el broker"
    }
  ],
  "lastModified": "2026-06-17T03:55:51.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1509006C-01A1-4D8F-81AF-B02F11464F06",
              "versionEndIncluding": "2.0.10",
              "versionStartIncluding": "1.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "emo@eclipse.org"
}