CVE-2024-42655: High severity nanomq nanomq vulnerability
Published Jul 29, 2025
·Updated
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
Affected Software
2 affected components
nanomq nanomq
emqx Nanomq=0.21.8
Remediation
Event History
Jul 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42655?
The severity of CVE-2024-42655 is rated as high due to the access control issue that allows unauthorized access to sensitive system topic messages.
2
How do I fix CVE-2024-42655?
To fix CVE-2024-42655, upgrade NanoMQ to a version that addresses the access control vulnerabilities.
3
Which versions of NanoMQ are affected by CVE-2024-42655?
CVE-2024-42655 affects NanoMQ version 0.21.10 and possibly earlier versions as well.
4
What type of vulnerability is CVE-2024-42655?
CVE-2024-42655 is an access control vulnerability associated with MQTT wildcard characters.
5
Can CVE-2024-42655 lead to data breaches?
Yes, CVE-2024-42655 can lead to data breaches by allowing attackers to access sensitive messages undetected.