Lucene search

K
osvGoogleOSV:CVE-2017-2893
HistoryNov 07, 2017 - 4:29 p.m.

CVE-2017-2893

2017-11-0716:29:00
Google
osv.dev
4

AI Score

6.5

Confidence

High

EPSS

0.217

Percentile

96.5%

An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

AI Score

6.5

Confidence

High

EPSS

0.217

Percentile

96.5%