Impact
An MQTT broker in Trueview 6.0.23.4 accepts client connections on TCP port 1883 without performing authentication. This omission allows any network‑connected attacker to establish an MQTT session and either publish messages to or subscribe from any topic. The lack of identity verification creates a direct channel for unauthorized disclosure or alteration of data carried through the broker.
Affected Systems
Trueview version 6.0.23.4, which runs an MQTT broker listening on TCP port 1883. The vulnerability affects every instance of this software that exposes that port to network traffic.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity, yet the EPSS score is below 1% and the vulnerability is not listed in CISA KEV, suggesting current exploitation activity is low. Nonetheless, the attack surface is large: any remote host with network access to port 1883 can exploit the flaw by simply opening a TCP connection. No special privileges, authentication, or additional conditions are required, making exploitation easy for an attacker with network reach.
OpenCVE Enrichment