Elevation of Privilege Vulnerability in Azure IoT Java SDK by Microsoft
CVE-2019-0729
9.8CRITICAL
What is CVE-2019-0729?
An Elevation of Privilege vulnerability in the Azure IoT Java SDK permits attackers to predict the randomness of symmetric keys generated for encryption. This flaw can potentially allow unauthorized access to sensitive data, compromising the integrity of IoT devices utilizing this SDK. Proper precautions should be taken to mitigate risks associated with this vulnerability.
Affected Version(s)
Java SDK for Azure IoT = unspecified