CVE-2019-17389: Riot-OS Riot

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.

Affected products

Published 2019-10-09. Last modified 2026-06-17.