Impact
The vulnerability in Trueview 6.0.23.4 allows attackers to connect to the MQTT broker on TCP port 1883 without authentication and to publish or subscribe to any topic. This lack of identity verification enables unauthorized disclosure or manipulation of MQTT messages, potentially compromising confidentiality, integrity, and availability of data transmitted through the broker. The weakness involves improper access control, specifically missing authentication requirements for a critical communication service.
Affected Systems
Trueview Trueview 6.0.23.4, which exposes an MQTT broker listening on TCP port 1883. The affected system is any component running this version of the Trueview software.
Risk and Exploitability
The vulnerability has no EPSS score and is not listed in CISA KEV, but the attack surface is large: any remote host with network connectivity to the MQTT port can exploit it. Because authentication is entirely absent, exploitation requires only the ability to open a TCP connection, making it highly feasible. The lack of mitigation information from the vendor indicates that a patch or update is essential to reduce this risk.
OpenCVE Enrichment