CVE-2024-45038 is a denial-of-service vulnerability affecting Meshtastic device firmware, specifically in its MQTT handling. This flaw allows an unauthenticated attacker to disrupt the service with low complexity over the network. The vulnerability has a CVSS score of 7.5 (HIGH) due to its potential for high availability impact. While there are no known active exploits, public exploit code, or significant community discussion, users are strongly advised to update to firmware version 2.4.1 or newer, especially those using private MQTT servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.1CPE matchmatch criteria | cpe:2.3:o:meshtastic:meshtastic_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.