Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-23664

Опубликовано: 10 мар. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

Azure IoT Explorer Information Disclosure Vulnerability

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability?

This vulnerability could allow an attacker with network access to the exposed Azure IoT Explorer API port to view sensitive data that the application makes available without authentication. Depending on how the application is used, this may include file contents from the host system, directory listings, IoT device data or configuration details, and metadata retrieved through server-side request forgery (SSRF), such as Azure Instance Metadata Service (IMDS) information.

Обновления

ПродуктСтатьяОбновление
Azure IoT Explorer

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 27%
0.00097
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
17 дней назад

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
github
17 дней назад

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.5
fstec
17 дней назад

Уязвимость программного обеспечения Azure IoT Explorer, связанная с недостаточным ограничением канала связи для заданных конечных точек, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 27%
0.00097
Низкий

7.5 High

CVSS3