CVE-2019-17389: Riot-OS Riot
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.
Affected products
- Riot-OS Riot: version 2019.07 only
Published 2019-10-09. Last modified 2026-06-17.