Vulnerability Description
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emqx | Nanomq | 0.21.8 |
Related Weaknesses (CWE)
References
- https://github.com/nanomq/nanomqProduct
- https://github.com/nanomq/nanomq/issues/1782#issuecomment-2171025812ExploitIssue TrackingPatch
- https://github.com/songxpu/bug_report/blob/master/MQTT/NanoMQ/CVE-2024-42655.mdExploitThird Party Advisory
FAQ
What is CVE-2024-42655?
CVE-2024-42655 is a vulnerability with a CVSS score of 8.8 (HIGH). An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
How severe is CVE-2024-42655?
CVE-2024-42655 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42655?
Check the references section above for vendor advisories and patch information. Affected products include: Emqx Nanomq.