eclipse mosquitto CVE-2018-12551 is a vulnerability in Eclipse Mosquitto
Published on March 27, 2019

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and get access to the broker by using the malformed username. In particular, a blank line will be treated as a valid empty username. Other security measures are unaffected. Users who have only used the mosquitto_passwd utility to create and modify their password files are unaffected by this vulnerability.

NVD

Weakness Type

Improper Check or Handling of Exceptional Conditions

The software does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the software.


Products Associated with CVE-2018-12551

Want to know whenever a new CVE is published for Eclipse Mosquitto? stack.watch will email you.

 

Affected Versions

The Eclipse Foundation Eclipse Mosquitto:

Exploit Probability

EPSS
0.71%
Percentile
71.96%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.