CVE-2018-18764 is a critical arbitrary memory read vulnerability affecting Cesanta Mongoose 6.13, specifically within its MQTT packet-parsing functionality. This heap-based buffer over-read, triggered by a specially crafted MQTT SUBSCRIBE packet, can lead to information disclosure and denial of service. With a CVSS score of 9.1 (CRITICAL), it presents a severe risk as it can be exploited remotely over the network without user interaction. While there is no known active exploitation, publicly available exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.13CPE matchmatch criteria | cpe:2.3:a:cesanta:mongoose:6.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.