CVE-2018-11615 is a denial-of-service vulnerability affecting npm mosca 2.8.1, stemming from improper handling of crafted regular expressions in topic processing. This allows unauthenticated remote attackers to crash the MQTT broker, denying service to legitimate users. With a CVSS score of 7.5 (High), it presents a significant availability risk due to its network-based attack vector and low attack complexity. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and there's minimal community discussion or media coverage, its EPSS score indicates a higher than average potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.1CPE matchmatch criteria | cpe:2.3:a:mosca_project:mosca:2.8.1:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.