VYPR

Amazon Web Services AWS C Io

by Amazon

CVEs (3)

  • CVE-2021-40831MedNov 23, 2021
    risk 0.34cvss 6.3epss 0.01

    The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA has been “overridden”. TLS handshakes will…

  • CVE-2021-40830MedNov 23, 2021
    risk 0.34cvss 6.3epss 0.00

    The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the…

  • CVE-2021-40828MedNov 23, 2021
    risk 0.34cvss 6.3epss 0.00

    Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding…