CVE-2020-17002 describes a critical security feature bypass vulnerability within the Microsoft C SDK for Azure IoT. This flaw, with a CVSS score of 9.1, allows an unauthenticated attacker to remotely compromise confidentiality and integrity with low attack complexity. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< lts_07_2020_ref02CPE matchmatch criteria | cpe:2.3:a:microsoft:c_sdk_for_azure_iot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.