CVE-2021-40831
CVE-2021-40831 — Missing SNI validation and inconsistent CA override function behavior within AWS IoT Device SDKs on Apple devices
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA has been “overridden”. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with access to a host’s trust stores or are able to compromise a certificate authority already in the host's trust store (note: the attacker must also be able to spoof DNS in this case) may be able to use this issue to bypass CA pinning. An attacker could then spoof the MQTT broker, and either drop traffic and/or respond with the attacker's data, but they would not be able to forward this data on to the MQTT broker because the attacker would still need the user's private keys to authenticate against…
Published Updated Sources: cvelistV5, F-SecureUS
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
1%
chance of exploitation in 30 days
CVSS base
6.3
MEDIUM
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (5)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 6.3 | CVSS 3.1 | MEDIUM | — | — | cvelistV5 |
Detection
Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.
- Search application, proxy, and WAF logs for requests touching /or.
References
5 on the record
- github.com/awslabs/aws-c-io/
x_refsource_MISC
- github.com/aws/aws-iot-device-sdk-cpp-v2
x_refsource_MISC
- github.com/aws/aws-iot-device-sdk-python-v2
x_refsource_MISC
- github.com/aws/aws-iot-device-sdk-java-v2
x_refsource_MISC
- github.com/aws/aws-iot-device-sdk-js-v2
x_refsource_MISC
Elsewhere on this site
- amazon web servicesevery CVE for this vendor
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.