Severity
9.8CRITICAL
EPSS
0.4%
top 41.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 2.2 | Impact: 5.2

🔴Vulnerability Details

2
CVEList
PHOENIX CONTACT: Out of bounds write only memory access2024-03-12
GHSA
GHSA-3p73-75xq-v9wv: An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack2024-03-12
CVE-2024-26001 (CRITICAL CVSS 9.8) | An unauthenticated remote attacker | cvebase.io