Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-24087

Опубликовано: 09 фев. 2021
Источник: msrc
CVSS3: 7
EPSS Низкий

Описание

Azure IoT CLI extension Elevation of Privilege Vulnerability

FAQ

What can an attacker do with this vulnerability?

An elevation of privilege vulnerability exists in the way Azure CLI and Azure IoT CLI extension generates new symmetric keys for encryption, allowing an attacker to predict the randomness of the key. An attacker could derive the keys from the way they are generated and use them to access a user's IoT hub.

How do I know if I need to install the update?

This update addresses the vulnerability by randomizing the key generation within Azure IoT CLI extension. https://github.com/Azure/azure-iot-cli-extension/pull/279/files https://docs.microsoft.com/en-us/cli/azure/release-notes-azure-cli?tabs=azure-cli#december-29-2020

Which versions are affected?

IoT extension versions affected are 0.10.2 – 0.10.6 All versions before 2.17.0 in Azure CLI are affected

Обновления

ПродуктСтатьяОбновление
azure-iot-cli-extension

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 34%
0.00138
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
nvd
почти 5 лет назад

Azure IoT CLI extension Elevation of Privilege Vulnerability

CVSS3: 7
github
больше 3 лет назад

Azure IoT CLI extension Elevation of Privilege Vulnerability

CVSS3: 7
fstec
почти 5 лет назад

Уязвимость интерфейса командной строки (CLI) платформы Azure IoT, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 34%
0.00138
Низкий

7 High

CVSS3