Remote Code Execution Vulnerability in Azure IoT Hub Device Client SDK
CVE-2018-8531

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
10 October 2018

What is CVE-2018-8531?

A remote code execution vulnerability has been identified in the Azure IoT Hub Device Client SDK. This issue arises from improper memory access when using the MQTT protocol, potentially allowing an attacker to execute arbitrary code on affected systems. Azure IoT Edge and the Hub Device Client SDK are at risk, which could lead to unauthorized access and manipulation. Organizations using these Azure services should assess their deployments and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

Azure IoT Edge Azure IoT Edge

Hub Device Client SDK Azure IoT

References

EPSS Score

18% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.