AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12551

HIGH · CVSS 8.1 EPSS 1.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-03-27 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. See the original NVD description below for full technical details.

CVE
CVE-2018-12551
Severity
HIGH
CVSS
8.1
EPSS
1.47%

Original NVD Description

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and get access to the broker by using the malformed username. In particular, a blank line will be treated as a valid empty username. Other security measures are unaffected. Users who have only used the mosquitto_passwd utility to create and modify their password files are unaffected by this vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)