VYPR

Hono

by Eclipse

CVEs (2)

  • CVE-2020-27220HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.01

    The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target…

  • CVE-2020-27217HigNov 13, 2020
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link…