CVE-2021-40831 affects AWS IoT Device SDK v2 for Java, Python, C++, and Node.js on macOS, where a user-supplied Certificate Authority (CA) is appended rather than overriding the system’s trust store, and SNI validation is not enforced. This allows TLS handshakes to succeed if verified by either the user-supplied CA or the system's default trust-store. With a CVSS score of 7.2 (HIGH), this vulnerability could allow attackers with access to a host's trust stores or compromised CAs to spoof the MQTT broker, potentially dropping or altering traffic, though they cannot forward data without the user's private keys. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.10.7CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_aws-c-io:0.10.7:*:*:*:*:*:*:* | ||
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_internet_of_things_device_software_development_kit_v2:*:*:*:*:*:java:*:* | ||
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_internet_of_things_device_software_development_kit_v2:*:*:*:*:*:node.js:*:* | ||
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_internet_of_things_device_software_development_kit_v2:*:*:*:*:*:python:*:* | ||
< 1.14.0CPE matchmatch criteria | cpe:2.3:a:amazon:amazon_web_services_internet_of_things_device_software_development_kit_v2:*:*:*:*:*:c\+\+:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.