CVE-2017-7652 describes a denial-of-service vulnerability in Eclipse Mosquitto versions 1.4.14 and earlier, affecting Debian Linux and Mosquitto distributions. When a Mosquitto instance with a configuration file receives a HUP signal, it attempts to reload the configuration. If the server has reached its file descriptor limit due to numerous client connections, this reload fails, potentially leading to service disruption. Rated with a CVSS v3 score of 7.5 (HIGH), this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability. While requiring low privileges, the attack complexity is high due to the prerequisite of exhausting file descriptors. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, <= 1.4.14CPE matchmatch criteria | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.