peter bassill · operator
$ cve CVE-2017-2892 JSON

CVE-2017-2892

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of service and remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2017-11-07
Last modified2026-06-17

Affected (1)

VendorProduct
cesantamongoose

References

→ the Explorer  ·  watch your stack  ·  NVD