Meshtastic Firmware Vulnerability: Update Right Away
CVE-2024-45038
7.5HIGH
What is CVE-2024-45038?
The Meshtastic device firmware enables the operation of an open-source, decentralized mesh network on affordable low-power devices. This firmware has been identified with a vulnerability related to denial of service originating from improper handling of MQTT protocols. This issue affects users particularly those utilizing privately hosted MQTT servers. To safeguard against potential service interruptions, it is highly recommended that all users promptly upgrade to version 2.4.1 or a newer stable release of the firmware. Currently, there are no known workaround methods to avoid this vulnerability.
Affected Version(s)
firmware < 2.4.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved