#VU17651 Cryptographic issues in Java SDK for Azure IoT - CVE-2019-0729
Published: February 13, 2019
Vulnerability identifier: #VU17651
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-0729
CWE-ID: CWE-310
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Java SDK for Azure IoT
Java SDK for Azure IoT
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote attacker to elevate privileges on the device.
The vulnerability exists due to Azure IoT Java SDK generates predictable symmetric keys for encryption. An attacker can derive the keys from the way they are generated and use them to access a user's IoT hub.
Remediation
Install updates from vendor's website.