Amazon AWS IoT Device SDK是美国亚马逊(Amazon)公司的 MIT 开源许可下的 C 源文件集合,可用于嵌入式应用程序以将 IoT 设备安全地连接到 AWS IoT Core。它包括一个 MQTT、JSON 解析器和 AWS IoT Device Shadow 库。它以源代码形式分发,旨在与应用程序代码、其他库以及可选的 RTOS(实时操作系统)一起构建到客户固件中。 Amazon AWS IoT Device SDK v2存在安全漏洞,该漏洞源于在TLS握手期间没有验证服务器证
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Amazon Web Services | AWS IoT Device SDK v2 for Java | unspecified ~ 1.3.3 | - |
|
| Amazon Web Services | AWS IoT Device SDK v2 for Python | unspecified ~ 1.5.18 | - |
|
| Amazon Web Services | AWS IoT Device SDK v2 for C++ | unspecified ~ 1.12.7 | - |
|
| Amazon Web Services | AWS IoT Device SDK v2 for Node.js | unspecified ~ 1.5.3 | - |
|
| Amazon Web Services | AWS-C-IO | 0.9.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-40829 | 6.3 MEDIUM | TLS hostname validation issues within AWS IoT Device SDKs on macOS |
| CVE-2021-40830 | 6.3 MEDIUM | Inconsistent CA override function behavior within AWS IoT Device SDKs on Unix systems |
| CVE-2021-40831 | 6.3 MEDIUM | Missing SNI validation and inconsistent CA override function behavior within AWS IoT Devic |
No comments yet