AWS IoT Python 设备 SDK(版本 1.5.3 至 1.6.0)在 Python 3.7 及更高版本上的 MQTT 客户端 TLS 连接层中,存在证书验证不当的问题(具体表现为主机名不匹配未被正确校验)。此漏洞可能被中间人攻击者利用,通过一个由设备信任存储区中证书颁发机构(CA)签发的、指向无关主机名的证书,冒充 AWS IoT Core 端点,从而窃听设备遥测数据,并向设备注入任意 MQTT 消息,使设备误认为这些消息是合法可信的。 要修复此问题,用户应升级至版本 1.6.1。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | AWSIoTPythonSDK | 1.5.3≤ 1.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWSIoTPythonSDK | 1.5.3 ~ 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet