CVE-2024-39792: NGINX Plus MQTT vulnerability
When NGINX Plus is configured to use the MQTT filter module, undisclosed requests can cause an increase in memory resource utilization.
Other sources
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39792?
The severity of CVE-2024-39792 has not been explicitly disclosed, but it impacts memory resource utilization, which could lead to performance issues.
How do I fix CVE-2024-39792?
To fix CVE-2024-39792, ensure you are using the latest versions of NGINX Plus, specifically versions after r32, as they may contain mitigations or fixes.
What are the affected versions of NGINX Plus for CVE-2024-39792?
The affected versions of NGINX Plus for CVE-2024-39792 include r30, r30-p1, r30-p2, r31, r31-p1, and r32.
What type of vulnerability is CVE-2024-39792?
CVE-2024-39792 involves an increase in memory resource utilization when using the MQTT filter and pre-read modules in NGINX Plus.
Can CVE-2024-39792 lead to a denial of service?
Yes, CVE-2024-39792 can potentially lead to a denial of service due to increased memory consumption by undisclosed requests.