{"document":{"acknowledgments":[{"organization":"CERTVDE","summary":"Coordination","urls":["https://certvde.com/en/"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3-1/specification-document","text":"Medium"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"The ADS-TEC firewall products IRF1000, IRF2000, and IRF3000 include Eclipse Mosquitto, affected by multiple vulnerabilities. Exploitation requires a compromised upstream MQTT broker, limiting direct device exposure.","title":"Summary"},{"category":"description","text":"Exploitation could result in denial-of-service (DoS) or Mosquitto crashes. Remote code execution (RCE) is theoretically possible but mitigated by security hardening and user-level process isolation.","title":"Impact"},{"category":"description","text":"Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.","title":"Mitigation"},{"category":"description","text":"Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@ads-tec.de","name":"ads-tec Industrial IT GmbH","namespace":"https://www.ads-tec-iit.com"},"references":[{"category":"self","summary":"VDE-2025-033: ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products - HTML","url":"https://certvde.com/en/advisories/VDE-2025-033/"},{"category":"self","summary":"VDE-2025-033: ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products - CSAF","url":"https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-033.json"}],"title":"ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products","tracking":{"aliases":["VDE-2025-033","ADS2025001"],"current_release_date":"2025-04-14T10:00:00.000Z","generator":{"date":"2025-04-04T07:52:10.569Z","engine":{"name":"Secvisogram","version":"2.5.21"}},"id":"VDE-2025-033","initial_release_date":"2025-04-14T10:00:00.000Z","revision_history":[{"date":"2025-04-14T10:00:00.000Z","number":"1","summary":"Initial revision"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"DVG-IRF1401","product":{"name":"DVG-IRF1401","product_id":"CSAFPID-11001"}},{"category":"product_name","name":"DVG-IRF1421","product":{"name":"DVG-IRF1421","product_id":"CSAFPID-11002"}}],"category":"product_family","name":"IRF1000"},{"branches":[{"category":"product_name","name":"DVG-IRF2200","product":{"name":"DVG-IRF2200","product_id":"CSAFPID-11003"}},{"category":"product_name","name":"DVG-IRF2100","product":{"name":"DVG-IRF2100","product_id":"CSAFPID-11004"}},{"category":"product_name","name":"DVG-IRF2220","product":{"name":"DVG-IRF2220","product_id":"CSAFPID-11005"}},{"category":"product_name","name":"DVG-IRF2621","product":{"name":"DVG-IRF2621","product_id":"CSAFPID-11006"}},{"category":"product_name","name":"DVG-IRF2601","product":{"name":"DVG-IRF2601","product_id":"CSAFPID-11007"}}],"category":"product_family","name":"IRF2000"},{"branches":[{"category":"product_name","name":"DVG-IRF3401","product":{"name":"DVG-IRF3401","product_id":"CSAFPID-11008"}},{"category":"product_name","name":"DVG-IRF3421","product":{"name":"DVG-IRF3421","product_id":"CSAFPID-11009"}},{"category":"product_name","name":" DVG-IRF3801","product":{"name":"DVG-IRF3801","product_id":"CSAFPID-11010"}},{"category":"product_name","name":" DVG-IRF3821","product":{"name":"DVG-IRF3821","product_id":"CSAFPID-11011"}}],"category":"product_family","name":"IRF3000"}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<2.1.0","product":{"name":"Firmware <2.1.0","product_id":"CSAFPID-21001"}},{"category":"product_version_range","name":"<6.1.0","product":{"name":"Firmware <6.1.0","product_id":"CSAFPID-21002"}},{"category":"product_version","name":"2.1.0","product":{"name":"Firmware 2.1.0","product_id":"CSAFPID-22001"}},{"category":"product_version","name":"6.1.0","product":{"name":"Firmware 6.1.0","product_id":"CSAFPID-22002"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"ads-tec Industrial IT GmbH"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006","CSAFPID-32007","CSAFPID-32008","CSAFPID-32009","CSAFPID-32010","CSAFPID-32011"],"summary":"Fixed products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF1401","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF1421","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <6.1.0 installed on DVG-IRF2200","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware <6.1.0 installed on DVG-IRF2100","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware <6.1.0 installed on DVG-IRF2220","product_id":"CSAFPID-31005"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"Firmware <6.1.0 installed on DVG-IRF2621","product_id":"CSAFPID-31006"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11006"},{"category":"installed_on","full_product_name":{"name":"Firmware <6.1.0 installed on DVG-IRF2601","product_id":"CSAFPID-31007"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11007"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF3401","product_id":"CSAFPID-31008"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11008"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF3421","product_id":"CSAFPID-31009"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11009"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF3801","product_id":"CSAFPID-31010"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11010"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.1.0 installed on DVG-IRF3821","product_id":"CSAFPID-31011"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11011"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF1401","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF1421","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 6.1.0 installed on DVG-IRF2200","product_id":"CSAFPID-32003"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware 6.1.0 installed on DVG-IRF2100","product_id":"CSAFPID-32004"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware 6.1.0 installed on DVG-IRF2220","product_id":"CSAFPID-32005"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"Firmware 6.1.0 installed on DVG-IRF2621","product_id":"CSAFPID-32006"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11006"},{"category":"installed_on","full_product_name":{"name":"Firmware 6.1.0 installed on DVG-IRF2601","product_id":"CSAFPID-32007"},"product_reference":"CSAFPID-22002","relates_to_product_reference":"CSAFPID-11007"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF3401","product_id":"CSAFPID-32008"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11008"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF3421","product_id":"CSAFPID-32009"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11009"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF3801","product_id":"CSAFPID-32010"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11010"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.1.0 installed on DVG-IRF3821","product_id":"CSAFPID-32011"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11011"}]},"vulnerabilities":[{"cve":"CVE-2024-3935","cwe":{"id":"CWE-415","name":"Double Free"},"notes":[{"audience":"all","category":"description","text":"In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing\nbridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur\nwith a subsequent crash of the broker.","title":"Vulnerability Description"},{"audience":"all","category":"details","text":"Adjusted CVSS Score (Product Context):  \nBase Score: 5.3 (Medium)  \nVector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\n\nJustification:  \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time.","title":"Vulnerability Characterisation"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006","CSAFPID-32007","CSAFPID-32008","CSAFPID-32009","CSAFPID-32010","CSAFPID-32011"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]},"remediations":[{"category":"mitigation","details":"Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":6.5,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":6.5,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]}],"title":"CVE-2024-3935"},{"cve":"CVE-2024-8376","cwe":{"id":"CWE-416","name":"Use After Free"},"notes":[{"audience":"all","category":"description","text":"In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heapuse-after-free by sending specific sequences of \"CONNECT\", \"DISCONNECT\", \"SUBSCRIBE\", \"UNSUBSCRIBE\"\nand \"PUBLISH\" packets","title":"Vulnerability Description"},{"audience":"all","category":"details","text":"Adjusted CVSS Score (Product Context):  \nBase Score: 5.9 (Medium)\nVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\n\nJustification:  \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time.","title":"Vulnerability Characterisation"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006","CSAFPID-32007","CSAFPID-32008","CSAFPID-32009","CSAFPID-32010","CSAFPID-32011"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]},"remediations":[{"category":"mitigation","details":"Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":7.5,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.5,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]}],"title":"CVE-2024-8376"},{"cve":"CVE-2024-10525","cwe":{"id":"CWE-122","name":"Heap-based Buffer Overflow"},"notes":[{"audience":"all","category":"description","text":"In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet\nwith no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its\non_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.","title":"Vulnerability Description"},{"audience":"all","category":"details","text":"Adjusted CVSS Score (Product Context):  \nBase Score: 5.6 (Medium)\nVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L\n\nJustification:  \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time.  \nC/I/A: Downgraded from High to Low due to process sandboxing and reduced privileges.","title":"Vulnerability Characterisation"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006","CSAFPID-32007","CSAFPID-32008","CSAFPID-32009","CSAFPID-32010","CSAFPID-32011"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]},"remediations":[{"category":"mitigation","details":"Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006","CSAFPID-31007","CSAFPID-31008","CSAFPID-31009","CSAFPID-31010","CSAFPID-31011"]}],"title":"CVE-2024-10525"}]}