Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-8119

Опубликовано: 08 мая 2018
Источник: msrc
EPSS Низкий

Описание

Azure IoT SDK Spoofing Vulnerability

A spoofing vulnerability exists for the C# and Java SDKs in the Azure IoT Device Provisioning AMQP Transport library which improperly validates certificates over the AMQP protocol. The same vulnerability exists for the C SDK in the Azure IoT Device library running on Windows devices. An attacker who successfully exploited this vulnerability could impersonate a server used during the provisioning process.

To exploit this vulnerability, an attacker would need to perform a man-in-the-middle (MitM) attack on the network that provisioning was taking place.

This security update addresses the vulnerability by correcting how the AMQP Transport library validates certificates.

Обновления

ПродуктСтатьяОбновление
C# SDK for Azure IoT
C SDK for Azure IoT
Java SDK for Azure IoT

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

Older Software Release

N/A

EPSS

Процентиль: 66%
0.0052
Низкий

Связанные уязвимости

CVSS3: 5.6
nvd
больше 7 лет назад

A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.

CVSS3: 5.6
github
больше 3 лет назад

A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.

EPSS

Процентиль: 66%
0.0052
Низкий