CVE-2024-38157 is a high-severity Remote Code Execution vulnerability affecting the Microsoft Azure IoT Hub Device Client SDK. An attacker with local access and high attack complexity could achieve full compromise of confidentiality, integrity, and availability. While not currently exploited in the wild and lacking public exploit code, it has garnered some community discussion and media coverage, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.1CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_iot_hub_device_client_sdk:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.12.1CPE match | cpe:2.3:a:microsoft:azure_iot_hub_device_client_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.