Junglewise Threat Intelligence

CVE-2021-40828: PYSEC-2021-861 - Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions pr

CVE-2021-40828 · Severity: low · CVSS 3.1 · Published 2021-11-23

Technologies: aws-iot-device-sdk-v2 (npm), Amazon Web Services AWS IoT Device SDK v2 for Java, Amazon Web Services AWS IoT Device SDK v2 for Python, awsiotsdk (PyPI), Amazon Web Services AWS IoT Device SDK v2 for C++, software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk (Maven), Amazon Web Services AWS IoT Device SDK v2 for Node.js. Vendors: npm, Amazon Web Services, PyPI, Maven.

Executive brief

AWS IoT Device SDK v2 (for Java, Python, C++, and Node.js) is used by applications to connect to AWS IoT services securely. On Windows, when custom certificate authorities are configured, the SDK failed to verify the server's hostname during TLS connections, allowing an attacker on the same network to intercept and redirect traffic to a malicious server, potentially exposing IoT device credentials and data.

Technical details

The vulnerability is an improper certificate validation (CWE-295) affecting the TLS handshake implementation. When a custom Certificate Authority (CA) is added to the trust store on Windows, the SDK did not perform Server Name Indication (SNI) and hostname verification checks during TLS handshake, contrary to the implementation on other platforms. An attacker with adjacent network access could perform a man-in-the-middle (MITM) attack by presenting a valid certificate signed by the overridden CA but for a different hostname. The fix was included in aws-c-io submodule version 0.9.13 onward, with the following patched SDK versions: Java 1.3.3, Python 1.5.18, C++ 1.12.7, and Node.js 1.5.1.

Affected products

  • Amazon Web Services AWS IoT Device SDK v2 for Java prior to 1.3.3
  • Amazon Web Services AWS IoT Device SDK v2 for Python prior to 1.5.18
  • Amazon Web Services AWS IoT Device SDK v2 for C++ prior to 1.12.7
  • Amazon Web Services AWS IoT Device SDK v2 for Node.js prior to 1.5.1

Timeline

  • 2021-11-24: disclosed
  • 2021-11-24: patched: Fixes released for all affected SDK versions

References

Related threats