Impact
The vulnerability is a heap buffer over‑read in the NGINX worker process caused by the ngx_stream_mqtt_filter_module when it receives MQTT packets that exceed normal size bounds. This over‑read triggers an internal failure that results in a restart of the worker process. No evidence suggests data or configuration disclosure; the attack only causes temporary data plane disruption by bringing the affected process down.
Affected Systems
F5 distributed system products that embed NGINX Plus and enable the ngx_stream_mqtt_filter_module. Specific build numbers are not listed, and end‑of‑technical‑support versions are not considered. The vulnerability affects only the data plane; the control plane remains untouched.
Risk and Exploitability
The CVSS v3.1 score of 6.3 indicates moderate severity. The EPSS score is below 1 %, implying a low likelihood of exploitation at present. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog. The description indicates that an attacker requires only remote, unauthenticated access to the MQTT service port, suggesting the attack vector is remote network access to NGINX Plus instances with the module enabled.
OpenCVE Enrichment