CVE-2024-44775 describes a high-severity Denial of Service (DoS) vulnerability in kmqtt v0.2.7, an MQTT broker. This flaw allows a remote, unauthenticated attacker to crash the broker by sending a specially crafted MQTT CONNECT packet, triggering a Null Pointer Exception and immediate process termination. Despite its high CVSS score of 7.5, there is currently no public exploit code, it is not on CISA's KEV or Hot List, and it shows minimal community or media attention, indicating a low probability of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.7CPE matchmatch criteria | cpe:2.3:a:davidepianca98:kmqtt:0.2.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.