Remote Code Execution Vulnerability in Azure IoT Hub Device Client SDK
CVE-2018-8531
8.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 October 2018
Summary
A remote code execution vulnerability has been identified in the Azure IoT Hub Device Client SDK. This issue arises from improper memory access when using the MQTT protocol, potentially allowing an attacker to execute arbitrary code on affected systems. Azure IoT Edge and the Hub Device Client SDK are at risk, which could lead to unauthorized access and manipulation. Organizations using these Azure services should assess their deployments and apply necessary updates to mitigate this vulnerability.
Affected Version(s)
Azure IoT Edge Azure IoT Edge
Hub Device Client SDK Azure IoT
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved