CVE-2019-11777
—CVSS 3.1
7.5 high
EPSS
<1%p56
Published
()
Modified
Description
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.
- Vendors
- eclipse
- Products
- paho java client
- Weakness
- CWE-346, CWE-755
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.