EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingEasy

A penetration tester is evaluating the security of an IoT device, specifically a smart camera, which uses MQTT for communication. During their assessment, they discover that the camera publishes its live video feed to an MQTT topic without any form of authentication or encryption. Which of the following attack vectors is MOST directly exemplified by this vulnerability?

  1. AInsecure Data Transmission
  2. BDenial of Service (DoS)
  3. CCross-Site Scripting (XSS)
  4. DSQL Injection
Show answer & explanation

Correct answer: A. Insecure Data Transmission

The scenario describes an IoT device transmitting sensitive data (live video feed) over MQTT without authentication or encryption, which directly points to insecure data transmission. This allows unauthorized access to the data in transit.

Why the other options are wrong

  • B. While insecure transmission could lead to a DoS if exploited differently, the direct problem described is the lack of protection for the data itself, not service availability.
  • C. XSS is a web application vulnerability, not directly related to unauthenticated MQTT data transmission.
  • D. SQL Injection targets databases and is unrelated to the MQTT communication described.

Insecure Data Transmission (IoT)

A vulnerability in IoT devices where data is transmitted between devices or to cloud services without proper encryption or authentication, making it susceptible to eavesdropping and tampering.

  • Often due to weak or absent encryption protocols.
  • Can expose sensitive user data, device status, or operational information.
  • Common in protocols like MQTT or CoAP if not secured properly.

Memory trick: IoT devices need strong locks and secure roads for their data journeys.

More Mobile Platform, IoT, and OT Hacking questions