Meshtastic Firmware Vulnerability: Update Right Away
CVE-2024-45038

7.5HIGH

Key Information:

Vendor

Meshtastic

Status
Vendor
CVE Published:
27 August 2024

What is CVE-2024-45038?

The Meshtastic device firmware enables the operation of an open-source, decentralized mesh network on affordable low-power devices. This firmware has been identified with a vulnerability related to denial of service originating from improper handling of MQTT protocols. This issue affects users particularly those utilizing privately hosted MQTT servers. To safeguard against potential service interruptions, it is highly recommended that all users promptly upgrade to version 2.4.1 or a newer stable release of the firmware. Currently, there are no known workaround methods to avoid this vulnerability.

Affected Version(s)

firmware < 2.4.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.