Описание
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
Ссылки
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:microsoft:java_software_development_kit:-:*:*:*:*:azure_internet_of_things:*:*
EPSS
Процентиль: 80%
0.01415
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-330
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
EPSS
Процентиль: 80%
0.01415
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-330