Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
Community & Social
Sicherheitslücken (CVE)A rough week for safety.(02.10.2026 um 22:30 Uhr)
•
IT Security NachrichtenA.I. Agents: Cute, Cuddly and Maybe Catastrophically Dangerous?(02.10.2026 um 17:26 Uhr)
•••
IT Security NachrichtenCollection: Just Security 2026 Midterm Election Analysis and Commentary(02.10.2026 um 22:23 Uhr)
••
IT Security DownloadsGitHub Release: anthropics/claude-code v2.1.288 (02.10.2026)(02.10.2026 um 22:19 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vdesktop-v0.0.43 (02.10.2026)(02.10.2026 um 22:39 Uhr)
•••
Sicherheitslücken (CVE)A rough week for safety.(02.10.2026 um 22:30 Uhr)
•
IT Security NachrichtenA.I. Agents: Cute, Cuddly and Maybe Catastrophically Dangerous?(02.10.2026 um 17:26 Uhr)
•••
IT Security NachrichtenCollection: Just Security 2026 Midterm Election Analysis and Commentary(02.10.2026 um 22:23 Uhr)
••
IT Security DownloadsGitHub Release: anthropics/claude-code v2.1.288 (02.10.2026)(02.10.2026 um 22:19 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vdesktop-v0.0.43 (02.10.2026)(02.10.2026 um 22:39 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

USN-7441-1: Eclipse Mosquitto vulnerabilities

It was discovered that Eclipse Mosquitto client incorrectly handled memory when receiving a SUBACK packet. An attacker with a malicious broker could possibly…

Beitrag
0
Seite
0
↗ Quelle (ubuntu.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
It was discovered that Eclipse Mosquitto client incorrectly handled
memory when receiving a SUBACK packet. An attacker with a malicious
broker could possibly use this issue to execute arbitrary code or
cause a denial of service. (CVE-2024-10525)

Xiangpu Song discovered that Eclipse Mosquitto broker did not properly
manage memory under certain circumstances. A malicious client with a
remote connection could possibly use this issue to cause the broker to
crash resulting in a denial of service, or another unspecified impact.
This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-3935)

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
2 Indikatoren · Defanged · STIX 2.1
CVE-2024-10525CVE-2024-3935
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2024-10525
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
HIGH EXPLOITABLE · Index 50/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
0-Click
Authentifizierung
Erforderlich

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2024-10525
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2024-10-30T13:33:25.135814Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-7441-1: Eclipse Mosquitto vulnerabilities

Thematisch verwandte Begriffe: USN74411, Eclipse, Mosquitto, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag