CVE-2024-48077 is a High severity Denial of Service (DoS) vulnerability affecting NanoMQ v0.22.7, stemming from improper resource throttling. A remote attacker can exploit this by sending a crafted sequence of requests, saturating the recv-q queue and rapidly exhausting system file descriptors. This leads to a process crash, rendering the MQTT broker unavailable, and carries a CVSS score of 7.5. The attack is network-based with low complexity, requiring no privileges or user interaction. Currently, there is no evidence of active exploitation, nor are public exploit modules available, although the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.7CPE matchmatch criteria | cpe:2.3:a:emqx:nanomq:0.22.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.