The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.mdpi.com/1424-8220/20/10/2932 | third party advisory technical description |
https://doi.org/10.3390/s20102932 | third party advisory technical description |