CVE-2020-13849 Information
Feb 14, 2021
cve
Description
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client which allows remote attackers to cause a denial of service (loss of the ability to establish new connections) as demonstrated by SlowITe.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://doi.org/10.3390/s20102932 https://www.mdpi.com/1424-8220/20/10/2932
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: