CVE-2018-8531 is a remote code execution vulnerability in the Azure IoT Hub Device Client SDK when using the MQTT protocol, specifically due to memory corruption. This flaw impacts the Azure IoT Edge and the C# Software Development Kit. With a CVSS score of 8.8 (High), it poses a significant risk, allowing unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity, though user interaction is required. There is no evidence of active exploitation, nor are public exploits like Metasploit or ExploitDB available, and community discussion and media coverage have been minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_internet_of_things_edge:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:csharp_software_development_kit:*:*:*:*:*:azure_internet_of_things:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.