PT-2026-95074 · Amazon · Aws-Iot-Device-Sdk-Python
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AWS IoT Device SDK for Python versions 1.5.3 through 1.6.0
Description
Improper validation of certificates with host mismatch occurs in the MQTT client TLS connection layer, specifically affecting X.509 mutual authentication on port 8883 and WebSocket SigV4 on port 443. This flaw allows an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint by using a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. Consequently, an attacker can read device telemetry and inject arbitrary MQTT messages that the device processes as authentic.
Recommendations
Upgrade to version 1.6.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Iot-Device-Sdk-Python