CVE-2017-2894
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.
- Affected products
- Mongoose
- Cesanta Mongoose
- = 6.8
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 31.0% (98th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2017-11-07
CVE-2017-2894 at NVD
1 known exploit for CVE-2017-2894
Proof-of-concept code and exploit modules indexed by Sploitus