Remote Code Execution Vulnerability in Azure IoT Hub Device Client SDK
CVE-2018-8531

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 October 2018

Summary

A remote code execution vulnerability has been identified in the Azure IoT Hub Device Client SDK. This issue arises from improper memory access when using the MQTT protocol, potentially allowing an attacker to execute arbitrary code on affected systems. Azure IoT Edge and the Hub Device Client SDK are at risk, which could lead to unauthorized access and manipulation. Organizations using these Azure services should assess their deployments and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

Azure IoT Edge Azure IoT Edge

Hub Device Client SDK Azure IoT

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.