First published: Wed May 09 2018(Updated: )
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft C Software Development Kit | ||
Microsoft Csharp Software Development Kit | ||
Oracle Java Software Development Kit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8119 has a severity rating of important, indicating a significant risk to affected systems.
To fix CVE-2018-8119, update to the latest versions of the affected Azure IoT Device Provisioning SDKs that address the certificate validation issue.
CVE-2018-8119 affects the Microsoft C, Csharp, and Java Software Development Kits for Azure IoT.
CVE-2018-8119 is a spoofing vulnerability related to improper certificate validation over the AMQP protocol.
No specific workarounds exist for CVE-2018-8119; the recommended action is to apply the available updates.