DESCRIPTION LAST UPDATED: 2023-12-07
DEFAULT SEVERITY LEVEL: MEDIUM
This report identifies devices that have an accessible AMQP (Advanced Message Queueing Protocol) on port 5672/TCP.
AMQP is an open internet protocol for business messaging. It is often also used for IoT device management.
Even though it does allow for encrypted communications via TLS, many instances on the Internet are configured for cleartext authentication and message sharing. Furthermore in the past there have been multiple vulnerabilities discovered in AMQP broker software implementations that can allow for authentication bypass, interception of messages, remote code execution or denial of service and other attacks.
You can track latest AMQP scan results on the Shadowserver Dashboard.
For more information on our scanning efforts, check out our Internet scanning summary page.
Severity levels are described here.
This report was enabled as part of the European Union INEA CEF VARIoT project.
Filename: scan_amqp