Executive brief
The AWS IoT Device SDK v2 (used by applications to securely connect to AWS IoT services) failed to properly verify server certificate hostnames during TLS handshakes when custom certificate authorities were configured on macOS systems. An attacker with network access could intercept connections and present a valid but unrelated certificate, allowing them to eavesdrop on or tamper with sensitive IoT communications.
Technical details
The vulnerability is a certificate hostname verification bypass (CWE-295) in the TLS handshake implementation for Java, Python, C++, and Node.js versions of AWS IoT Device SDK v2 on macOS. When users overrode the default Certificate Authority (CA) trust store, the SDK failed to validate that the server's certificate hostname matched the intended connection target. An attacker on the network (adjacent or network-accessible, depending on deployment) could perform a man-in-the-middle attack by presenting a valid certificate signed by a trusted CA but for a different hostname, gaining read/write access to IoT device communications. The fix was delivered via the aws-c-io submodule version 0.10.5 and incorporated into patched SDK versions (Java 1.4.2, Python 1.6.1, C++ 1.12.7, Node.js 1.5.3).
Affected products
- Amazon Web Services AWS IoT Device SDK v2 for Java prior to 1.4.2 on macOS
- Amazon Web Services AWS IoT Device SDK v2 for Python prior to 1.6.1 on macOS
- Amazon Web Services AWS IoT Device SDK v2 for C++ prior to 1.12.7 on macOS
- Amazon Web Services AWS IoT Device SDK v2 for Node.js prior to 1.5.3 on macOS
- Amazon Web Services aws-c-io 0.10.4 on macOS
Timeline
- 2021-11-24: disclosed: Published to GitHub Advisory Database
- 2021-11-24: patched: Patches released: Java 1.4.2, Python 1.6.1, C++ 1.12.7, Node.js 1.5.3; aws-c-io 0.10.5+