VYPR
High severity7.5NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026

CVE-2020-13849

CVE-2020-13849

Description

The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.

Affected products

3
  • MQTT/MQTT2 versions
    cpe:2.3:a:mqtt:mqtt:3.1.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mqtt:mqtt:3.1.1:*:*:*:*:*:*:*
    • (no CPE)range: 3.1.1
  • MQTT protocol/MQTT protocoldescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.