Vulnerability CVE-2021-33175


Published: 2021-06-08

Description:
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts of memory, resulting in the application being terminated by the operating system.

Type:

CWE-770

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
EMQX -> Emq x broker 

 References:
https://www.synopsys.com/blogs/software-security/cyrc-advisory-rabbitmq-emqx-vernemq

Copyright 2024, cxsecurity.com

 

Back to Top