Executive brief
The AWS IoT Device SDK v2 (Java, Python, C++, Node.js) improperly manages certificate authorities on macOS, appending user-supplied CAs instead of overriding them and failing to enable SNI validation. An attacker with access to system trust stores or ability to compromise a trusted certificate authority could spoof the MQTT broker, intercept traffic, and inject malicious data—though they cannot complete authentication without the user's private keys.
Technical details
This vulnerability involves improper certificate management in the aws-tls-ctx-options-override-default-trust-store function on macOS. Instead of replacing the system's default trust store with a user-supplied CA, the SDK appends the user CA to the existing trust store, and SNI validation is not enabled when the CA has been "overridden." An attacker with access to the host's trust stores, or who can compromise a certificate authority already trusted by the system (and spoof DNS), can bypass CA pinning. The attacker can then perform a man-in-the-middle attack on MQTT connections, but lacks the user's private credentials needed to fully authenticate to the actual broker. Patches are available: aws-c-io has been updated, and fixed versions are available for all affected SDKs (Java 1.5.0+, Python 1.7.0+, C++ 1.14.0+, Node.js 1.6.0+).
Affected products
- Amazon Web Services AWS IoT Device SDK v2 for Java before 1.5.0, macOS only
- Amazon Web Services AWS IoT Device SDK v2 for Python before 1.7.0, macOS only
- Amazon Web Services AWS IoT Device SDK v2 for C++ before 1.14.0, macOS only
- Amazon Web Services AWS IoT Device SDK v2 for Node.js before 1.6.0, macOS only
- Amazon Web Services aws-c-io 0.10.7 and earlier, macOS only
Timeline
- 2021-11-24: disclosed: Vulnerability published on GitHub and NVD
- 2021-11-24: patched: Fixed versions released: Java 1.5.0+, Python 1.7.0+, C++ 1.14.0+, Node.js 1.6.0+