8.8
CVE-2021-40828
- EPSS 0.1%
- Published 23.11.2021 00:15:07
- Last modified 21.11.2024 06:24:51
- Source cve-notifications-us@f-secure.
- Teams watchlist Login
- Open Login
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust stores on Windows. This issue has been addressed in aws-c-io submodule versions 0.9.13 onward. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.3.3 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.5.18 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.12.7 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.5.3 on Microsoft Windows.
Data is provided by the National Vulnerability Database (NVD)
Amazon ≫ Amazon Web Services Aws-c-io Version < 0.9.13
Amazon ≫ Amazon Web Services Internet Of Things Device Software Development Kit V2 SwPlatformjava Version < 1.3.3
Amazon ≫ Amazon Web Services Internet Of Things Device Software Development Kit V2 SwPlatformnode.js Version < 1.5.1
Amazon ≫ Amazon Web Services Internet Of Things Device Software Development Kit V2 SwPlatformpython Version < 1.5.18
Amazon ≫ Amazon Web Services Internet Of Things Device Software Development Kit V2 SwPlatformc++ Version < 1.12.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.25 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
cve-notifications-us@f-secure.com | 6.3 | 0.4 | 5.9 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.