Cryptographic issues in Java SDK for Azure IoT - CVE-2019-0729

 

Cryptographic issues in Java SDK for Azure IoT - CVE-2019-0729

Published: February 13, 2019


Vulnerability identifier: #VU17651
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0729
CWE-ID: CWE-310
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to elevate privileges on the device.

The vulnerability exists due to Azure IoT Java SDK generates predictable symmetric keys for encryption. An attacker can derive the keys from the way they are generated and use them to access a user's IoT hub.

Affected software

Java SDK for Azure IoT

How to mitigate CVE-2019-0729

Install updates from vendor's website.


External References

Related Security Bulletins