Sploitus

CVE-2017-2894

1 known exploit for CVE-2017-2894

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

Affected products
Mongoose
Cesanta Mongoose
= 6.8
CVSS 3.1
9.8 CRITICAL
EPSS
31.0% (98th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2017-11-07
CVE-2017-2894 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2017-2894

Proof-of-concept code and exploit modules indexed by Sploitus