Impact
An issue in EMQ NanoMQ version 0.24.9 permits a remote attacker to trigger a denial of service by invoking the nni_qos_db_set function in broker_tcp.c. The flaw maps to CWE-400 Uncontrolled Resource Consumption and CWE-772 Improper Release of Resources, indicating that the broker can become unresponsive after receiving malformed input.
Affected Systems
EMQ NanoMQ version 0.24.9. No vendor name is specified in the data, but the referenced repository indicates that the project is developed by EMQ.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the high severity range, while the EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network connection that reaches the EMQ NanoMQ broker and invokes the vulnerable function; no special privileges beyond network reachability to the broker are required.
OpenCVE Enrichment