CVE-2018-8119High

Azure IoT SDK Spoofing Vulnerability

Published
May 8, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A spoofing vulnerability exists for the C# and Java SDKs in the Azure IoT Device Provisioning AMQP Transport library which improperly validates certificates over the AMQP protocol. The same vulnerability exists for the C SDK in the Azure IoT Device library running on Windows devices. An attacker who successfully exploited this vulnerability could impersonate a server used during the provisioning process. To exploit this vulnerability, an attacker would need to perform a man-in-the-middle (MitM) attack on the network that provisioning was taking place. This security update addresses the vulnerability by correcting how the AMQP Transport library validates certificates.

🎯 Affected products3

  • C SDK for Azure IoT
  • C# SDK for Azure IoT
  • Java SDK for Azure IoT

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (4)