PT-2026-95074 · Amazon · Aws-Iot-Device-Sdk-Python

·

CVE-2026-92943

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AWS IoT Device SDK for Python versions 1.5.3 through 1.6.0
Description Improper validation of certificates with host mismatch occurs in the MQTT client TLS connection layer, specifically affecting X.509 mutual authentication on port 8883 and WebSocket SigV4 on port 443. This flaw allows an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint by using a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. Consequently, an attacker can read device telemetry and inject arbitrary MQTT messages that the device processes as authentic.
Recommendations Upgrade to version 1.6.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92943
GHSA-G7VP-3RXX-V25R

Affected Products

Aws-Iot-Device-Sdk-Python