An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/106966 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0729 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/106966 | Third Party Advisory VDB Entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0729 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/106966 - Third Party Advisory, VDB Entry | |
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0729 - Patch, Vendor Advisory |
Information
Published : 2019-03-05 23:29
Updated : 2024-11-21 04:17
NVD link : CVE-2019-0729
Mitre link : CVE-2019-0729
CVE.ORG link : CVE-2019-0729
JSON object : View
Products Affected
microsoft
- java_software_development_kit
CWE
CWE-330
Use of Insufficiently Random Values