
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-28349 affects ChirpStack Network Server 3.9.0, where an inaccurate frame deduplication process allows a malicious gateway to perform uplink Denial of Service via manipulated frequency values (NVD).
The vulnerability exists in the frame deduplication process where a malicious gateway can manipulate the frequency field in MQTT messages. When collecting uplink frames, the Network Server uses Redis sets to store messages with the same phyPayload. The TXInfo (containing frequency) is set to the last payload in the set, which can be exploited by sending malicious messages with invalid frequency values (CyberArk).
When successfully exploited, this vulnerability results in a Denial of Service (DoS) on uplinks, particularly affecting Class A devices. For alarm or detection devices (e.g., fire, flood, or intrusion), this could render them completely useless as uplinks would not be received by the application layer (CyberArk).
The attack requires a compromised or malicious gateway in the network. If the gateway has read/write permissions on all uplink topics on the MQTT broker, the attack can target any device in the Network. If the gateway only has write permission, the attack can only target devices within the gateway's range (CyberArk).
The issue has been fixed in ChirpStack Network Server by adding the frequency to the collection key of the uplink frames and not allowing unregistered gateways to communicate with the Network Server. Additionally, proper MQTT Authorization configuration is recommended to limit the attack surface (CyberArk).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."