ID

VAR-201805-1058


CVE

CVE-2018-8119


TITLE

plural Azure IoT SDK Impersonation vulnerability in products

Trust: 0.8

sources: JVNDB: JVNDB-2018-005095

DESCRIPTION

A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. Microsoft C #, C, and Java SDK for Azure IoT are software development kits for Microsoft Azure (Microsoft) based on C #, C, and Java languages for developing Azure IoT (Internet of Things Platform) applications, respectively. An attacker could use this vulnerability to impersonate a server. Multiple Microsoft Azure IoT SDKs are prone to a security vulnerability that may allow attackers to conduct spoofing attacks. A man-in-the-middle attacker can exploit this issue to conduct spoofing attacks and perform unauthorized actions; other attacks are also possible

Trust: 2.97

sources: NVD: CVE-2018-8119 // JVNDB: JVNDB-2018-005095 // CNVD: CNVD-2018-11134 // CNNVD: CNNVD-201805-291 // BID: 104070

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11134

AFFECTED PRODUCTS

vendor:microsoftmodel:c software development kitscope:eqversion:*

Trust: 1.0

vendor:microsoftmodel:java software development kitscope:eqversion:*

Trust: 1.0

vendor:microsoftmodel:csharp software development kitscope:eqversion:*

Trust: 1.0

vendor:microsoftmodel:c# sdk for azure iotscope:eqversion:0

Trust: 0.9

vendor:microsoftmodel:java sdk for azure iotscope:eqversion:0

Trust: 0.9

vendor:microsoftmodel:c sdkscope:eqversion:for azure iot

Trust: 0.8

vendor:microsoftmodel:c# sdkscope:eqversion:for azure iot

Trust: 0.8

vendor:microsoftmodel:java sdkscope:eqversion:for azure iot

Trust: 0.8

vendor:microsoftmodel:c sdk for azure iot noscope: - version: -

Trust: 0.6

vendor:microsoftmodel:csharp software development kitscope:eqversion:azure_internet_of_things

Trust: 0.6

vendor:microsoftmodel:java software development kitscope:eqversion:azure_internet_of_things

Trust: 0.6

vendor:microsoftmodel:c software development kitscope:eqversion:azure_internet_of_things

Trust: 0.6

vendor:microsoftmodel:c sdk for azure iotscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-11134 // BID: 104070 // JVNDB: JVNDB-2018-005095 // CNNVD: CNNVD-201805-291 // NVD: CVE-2018-8119

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-8119
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-8119
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-11134
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201805-291
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2018-8119
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-11134
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-8119
baseSeverity: MEDIUM
baseScore: 5.6
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.2
impactScore: 3.4
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-11134 // JVNDB: JVNDB-2018-005095 // CNNVD: CNNVD-201805-291 // NVD: CVE-2018-8119

PROBLEMTYPE DATA

problemtype:CWE-295

Trust: 1.8

sources: JVNDB: JVNDB-2018-005095 // NVD: CVE-2018-8119

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-291

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201805-291

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005095

PATCH

title:CVE-2018-8119 | Azure IoT SDK Spoofing Vulnerabilityurl:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8119

Trust: 0.8

title:CVE-2018-8119 | Azure IoT SDK のなりすましの脆弱性url:https://portal.msrc.microsoft.com/ja-jp/security-guidance/advisory/CVE-2018-8119

Trust: 0.8

title:Patch for Microsoft Azure IoT SDK man-in-the-middle spoofing vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/131505

Trust: 0.6

title:Microsoft C# , C and Java SDK for Azure IoT Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79969

Trust: 0.6

sources: CNVD: CNVD-2018-11134 // JVNDB: JVNDB-2018-005095 // CNNVD: CNNVD-201805-291

EXTERNAL IDS

db:NVDid:CVE-2018-8119

Trust: 3.3

db:BIDid:104070

Trust: 1.9

db:JVNDBid:JVNDB-2018-005095

Trust: 0.8

db:CNVDid:CNVD-2018-11134

Trust: 0.6

db:NSFOCUSid:39660

Trust: 0.6

db:CNNVDid:CNNVD-201805-291

Trust: 0.6

sources: CNVD: CNVD-2018-11134 // BID: 104070 // JVNDB: JVNDB-2018-005095 // CNNVD: CNNVD-201805-291 // NVD: CVE-2018-8119

REFERENCES

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2018-8119

Trust: 2.5

url:https://tools.cisco.com/security/center/viewalert.x?alertid=57754&vs_f=alert%20rss&vs_cat=security%20intelligence&vs_type=rss&vs_p=microsoft%20azure%20iot%20sdk%20amqp%20transport%20library%20spoofing%20vulnerability&vs_k=1

Trust: 1.0

url:http://www.securityfocus.com/bid/104070

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-8119

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20180509-ms.html

Trust: 0.8

url:http://www.jpcert.or.jp/at/2018/at180021.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-8119

Trust: 0.8

url:http://www.nsfocus.net/vulndb/39660

Trust: 0.6

url:http://www.microsoft.com

Trust: 0.3

sources: CNVD: CNVD-2018-11134 // BID: 104070 // JVNDB: JVNDB-2018-005095 // CNNVD: CNNVD-201805-291 // NVD: CVE-2018-8119

CREDITS

Cristian Pop, Rajeev Vokkarne, John Spaith, and Tim Taylor of Azure IoT

Trust: 0.3

sources: BID: 104070

SOURCES

db:CNVDid:CNVD-2018-11134
db:BIDid:104070
db:JVNDBid:JVNDB-2018-005095
db:CNNVDid:CNNVD-201805-291
db:NVDid:CVE-2018-8119

LAST UPDATE DATE

2024-11-23T22:34:16.706000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11134date:2018-06-08T00:00:00
db:BIDid:104070date:2018-05-08T00:00:00
db:JVNDBid:JVNDB-2018-005095date:2018-07-05T00:00:00
db:CNNVDid:CNNVD-201805-291date:2018-05-10T00:00:00
db:NVDid:CVE-2018-8119date:2024-11-21T04:13:18.017

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11134date:2018-06-08T00:00:00
db:BIDid:104070date:2018-05-08T00:00:00
db:JVNDBid:JVNDB-2018-005095date:2018-07-05T00:00:00
db:CNNVDid:CNNVD-201805-291date:2018-05-10T00:00:00
db:NVDid:CVE-2018-8119date:2018-05-09T19:29:01.230