Rate Limiting Vulnerability in Meshtastic Open Source Mesh Networking Solution
CVE-2024-47065
2.7LOW
What is CVE-2024-47065?
Meshtastic, an open source mesh networking solution, has a vulnerability present in versions prior to 2.5.1 related to the handling of traceroute responses. Specifically, these responses are not subject to rate limiting, allowing for potential abuse. An attacker could exploit this flaw to induce a high volume of traceroute requests, receiving up to 100 samples in a mere two minutes. This could impact the positional confidentiality of network stations. Furthermore, the lack of rate limiting could lead to denial of service conditions, resulting in network disruptions. The vulnerability has been effectively addressed in version 2.5.1.
Affected Version(s)
firmware < 2.5.1