Azure IoT SDK
by Microsoft
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0729 | Cri | 0.64 | 9.8 | 0.03 | Mar 5, 2019 | An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0741 | Hig | 0.49 | 7.5 | 0.07 | Mar 5, 2019 | An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'. | ||
| CVE-2020-17002 | Hig | 0.48 | 7.4 | 0.03 | Dec 10, 2020 | Azure SDK for C Security Feature Bypass Vulnerability | ||
| CVE-2024-38158 | Hig | 0.46 | 7.0 | 0.00 | Aug 13, 2024 | Azure IoT SDK Remote Code Execution Vulnerability | ||
| CVE-2024-38157 | Hig | 0.46 | 7.0 | 0.00 | Aug 13, 2024 | Azure IoT SDK Remote Code Execution Vulnerability |
- risk 0.64cvss 9.8epss 0.03
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
- risk 0.49cvss 7.5epss 0.07
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.
- risk 0.48cvss 7.4epss 0.03
Azure SDK for C Security Feature Bypass Vulnerability
- risk 0.46cvss 7.0epss 0.00
Azure IoT SDK Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
Azure IoT SDK Remote Code Execution Vulnerability