Executive brief
Aedes is an open-source MQTT broker used to manage message queuing in IoT and real-time applications. A flaw in the packet writing logic fails to properly handle exceptions, allowing an attacker to send malformed packets that cause the broker to crash, leading to service unavailability.
Technical details
The vulnerability exists in lib/write.js of Aedes versions prior to 0.42.1, where exceptions occurring during packet writes to a stream are not properly caught or handled (CWE-755: Improper Handling of Exceptional Conditions). An attacker can send a specially crafted invalid MQTT packet over the network to trigger an unhandled exception. No authentication or user interaction is required since MQTT protocol handling occurs at the network layer. A successful exploit crashes the broker process, resulting in denial of service. The fix was released in version 0.42.1.
Affected products
- MoscaJS Aedes < 0.42.1
Timeline
- 2020-08-26: disclosed
- 2020-05-25: patched