Authentication Bypass in Eclipse Mosquitto Affected by Malformed Password File
CVE-2018-12551
8.1HIGH
What is CVE-2018-12551?
Eclipse Mosquitto versions 1.0 through 1.5.5 contain a vulnerability where malformed data in password files may be incorrectly recognized as valid credentials. This can allow attackers to bypass authentication, using malformed usernames (including blank lines) to gain unauthorized access to the service. Users employing the standard 'mosquitto_passwd' utility to manage password files remain unaffected by this issue. This vulnerability poses significant risks to the integrity and confidentiality of data managed by the broker.
Affected Version(s)
Eclipse Mosquitto 1.0
Eclipse Mosquitto <= 1.5.5
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved