CVE-2024-3935 describes a double free vulnerability in Eclipse Mosquitto versions 2.0.0 through 2.0.18. This flaw occurs when a broker is configured with an outgoing bridge connection using topic remapping, allowing a crafted PUBLISH packet from a remote connection to trigger a broker crash. Rated Medium severity (CVSS 6.5), it has a network attack vector, low attack complexity, and high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.19CPE matchmatch criteria | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.0.18CPE match | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.