CVE-2021-33175: High severity emq x broker vulnerability
Published Jun 8, 2021
·Updated
EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the handling of untrusted inputs. These inputs cause the message broker to consume large amounts of memory, resulting in the application being terminated by the operating system.
Affected Software
1 affected component
emqx Emq X Broker<4.2.8
Remediation
Event History
Jun 8, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-33175?
CVE-2021-33175 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2021-33175?
To mitigate CVE-2021-33175, upgrade EMQ X Broker to version 4.2.8 or later.
3
What causes CVE-2021-33175?
CVE-2021-33175 is caused by excessive memory consumption from handling untrusted inputs.
4
Which versions of EMQ X Broker are affected by CVE-2021-33175?
CVE-2021-33175 affects all EMQ X Broker versions prior to 4.2.8.
5
What impact does CVE-2021-33175 have on EMQ X Broker?
CVE-2021-33175 can lead to application termination due to excessive memory usage.