An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0729 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/106966 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-03-05 15:29
Updated : 2021-07-21 04:39
NVD link : CVE-2019-0729
Mitre link : CVE-2019-0729
JSON object : View
CWE
CWE-330
Use of Insufficiently Random Values
Products Affected
microsoft
- java_software_development_kit