PROTOCOL-OTHER -- Snort alerted on traffic known to exploit vulnerabilities in protocols that do not fit into one of the other protocol rule categories.
PROTOCOL-OTHER MQTT Connect control packet detected
This event is generated when a Cesanta Mongoose MQTT 'parse_mqtt' integer overflow attempt is detected. Impact: Attempted Denial of Service Possible out of bounds read/write Details: This affects Cesanta Mongoose versions prior to 6.16 Ease of Attack: Must be connected to a MQTT service to attack this
This rule occurs when an attacker connects to a MQTT service and sends buffer length information containing an integer overflow.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None