Authentication Bypass in Eclipse Mosquitto Affected by Malformed Password File
CVE-2018-12551

8.1HIGH

Key Information:

Vendor
CVE Published:
27 March 2019

What is CVE-2018-12551?

Eclipse Mosquitto versions 1.0 through 1.5.5 contain a vulnerability where malformed data in password files may be incorrectly recognized as valid credentials. This can allow attackers to bypass authentication, using malformed usernames (including blank lines) to gain unauthorized access to the service. Users employing the standard 'mosquitto_passwd' utility to manage password files remain unaffected by this issue. This vulnerability poses significant risks to the integrity and confidentiality of data managed by the broker.

Affected Version(s)

Eclipse Mosquitto 1.0

Eclipse Mosquitto <= 1.5.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.