vendor:
Mosquitto MQTT broker
by:
Riadh Bouchahoua
7.8
CVSS
HIGH
Unquoted Service Path
CWE
Product Name: Mosquitto MQTT broker
Affected Version From: 2.0.9
Affected Version To: 2.0.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 64 bits
2021
Eclipse Mosquitto MQTT broker 2.0.9 – ‘mosquitto’ Unquoted Service Path
The vulnerability allows an attacker to gain elevated privileges by exploiting an unquoted service path in Eclipse Mosquitto MQTT broker version 2.0.9. By manipulating the service path, an attacker can execute arbitrary code with elevated privileges.
Mitigation:
To mitigate this vulnerability, users are advised to install the latest version of Eclipse Mosquitto MQTT broker and ensure that the service path is properly quoted.