IoT & Hardware

Denial of Service

DoS in aedes MQTT broker

DoS on aedes broker because of incorrect error handling A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the…

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS34
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-13410
VENDORS
moscaJS
PUBLIC EXPLOIT
PoC public
CWE
CWE-755
PRODUCT
aedes MQTT broker
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

DoS on aedes broker because of incorrect error handling

A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the improper error handling in writeNumberCached while trying to create a packet for Publish Release which fails at stream.write() as the datatype is an undefined array with -1 number as it is the packet id of the packet.

Vulnerability details

Vulnerability details

CVE-2020-13410
CWE-755
High | 7.5

DoS on aedes broker because of incorrect error handling A specifically crafted payload which has published header and message length as 0 is sent to the server which crashes the server because of the improper error handling in writeNumberCached while trying

Auth:
None (remote)
Impact:
Denial of service
DISCLOSURE

Disclosure timeline

2020-05-18 reported to the vendor

2020-05-22 Issue was fixed.

Credits

Arun Magesh