Lucene search

K
cveIbmCVE-2014-0923
HistoryApr 15, 2014 - 11:13 p.m.

CVE-2014-0923

2014-04-1523:13:17
CWE-20
ibm
web.nvd.nist.gov
23
ibm
messagesight
cve-2014-0923
denial of service
remote attackers
mq telemetry transport
mqtt
authentication
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.4

Confidence

High

EPSS

0.008

Percentile

81.2%

IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.

Affected configurations

Nvd
Node
ibmmessagesight_jms_clientMatch1.0.0.0
OR
ibmmessagesight_jms_clientMatch1.0.0.1
OR
ibmmessagesight_jms_clientMatch1.1.0.0
AND
ibmmessagesightMatch-
VendorProductVersionCPE
ibmmessagesight_jms_client1.0.0.0cpe:2.3:a:ibm:messagesight_jms_client:1.0.0.0:*:*:*:*:*:*:*
ibmmessagesight_jms_client1.0.0.1cpe:2.3:a:ibm:messagesight_jms_client:1.0.0.1:*:*:*:*:*:*:*
ibmmessagesight_jms_client1.1.0.0cpe:2.3:a:ibm:messagesight_jms_client:1.1.0.0:*:*:*:*:*:*:*
ibmmessagesight-cpe:2.3:h:ibm:messagesight:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.4

Confidence

High

EPSS

0.008

Percentile

81.2%

Related for CVE-2014-0923