CVE-2018-8479 is a medium-severity spoofing vulnerability affecting the Azure IoT C SDK library when utilizing the HTTP protocol on Windows platforms. This flaw could allow an attacker to spoof devices within the Azure IoT Device Provisioning service. The vulnerability has a CVSS score of 5.6, indicating a network-based attack with high attack complexity, potentially leading to low impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, though it received some community and media attention at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:c_software_development_kit:*:*:*:*:*:azure_internet_of_things:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:java_software_development_kit:*:*:*:*:*:azure_internet_of_things:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.