CVE-2024-42648
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-07-14
Last updated on: 2025-07-16
Assigner: MITRE
Description
Description
NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| emqx | nanomq | 0.22.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-122 | A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc(). |
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
NanoMQ version 0.22.10 contains a heap overflow vulnerability that can be triggered by an attacker sending a specially crafted CONNECT message. This vulnerability allows the attacker to cause a Denial of Service (DoS) condition in the affected system.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing an attacker to cause a Denial of Service (DoS) on your NanoMQ service, potentially making it unavailable or unstable due to the heap overflow triggered by a crafted CONNECT message.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70