Vulnerability Description
A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Azure Internet Of Things Edge | - |
| Microsoft | Csharp Software Development Kit | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105472Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8531PatchVendor Advisory
- http://www.securityfocus.com/bid/105472Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8531PatchVendor Advisory
FAQ
What is CVE-2018-8531?
CVE-2018-8531 is a vulnerability with a CVSS score of 8.8 (HIGH). A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerab...
How severe is CVE-2018-8531?
CVE-2018-8531 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-8531?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Azure Internet Of Things Edge, Microsoft Csharp Software Development Kit.