CVE-2020-10071: Insufficient publish message length validation in MQTT
Published Jun 5, 2020
·Updated
The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.
Affected Software
1 affected component
zephyrproject zephyr<=2.2.0
Remediation
Event History
Jun 5, 2020
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-10071?
CVE-2020-10071 has a high severity rating due to its potential for buffer overflow and remote code execution.
2
How do I fix CVE-2020-10071?
To fix CVE-2020-10071, update to a version of Zephyr later than 2.2.0 where the vulnerability is patched.
3
What systems are affected by CVE-2020-10071?
CVE-2020-10071 affects Zephyr versions 2.2.0 and later.
4
What type of vulnerability is CVE-2020-10071?
CVE-2020-10071 is characterized as a buffer overflow vulnerability in the MQTT parsing code.
5
Can CVE-2020-10071 be exploited remotely?
Yes, CVE-2020-10071 can allow for remote code execution due to insufficient length field checking.