Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-23662

Опубликовано: 10 мар. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

Azure IoT Explorer Information Disclosure Vulnerability

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability?

This vulnerability could allow an attacker on the same network to view IoT device telemetry that is sent through the affected WebSocket connection. The exposed data may include real‑time device readings, operational status information, or device‑specific metadata transmitted by the application. The exact information disclosed depends on the telemetry configured by the device.

Обновления

ПродуктСтатьяОбновление
Azure IoT Explorer

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 51%
0.00724
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
github
5 месяцев назад

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость программного обеспечения Azure IoT Explorer, связанная с передачей критичной информации открытым текстом, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 51%
0.00724
Низкий

7.5 High

CVSS3