An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
References
| Link | Resource |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0729 | Patch Vendor Advisory |
| http://www.securityfocus.com/bid/106966 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-03-05 23:29
Updated : 2021-07-21 11:39
NVD link : CVE-2019-0729
Mitre link : CVE-2019-0729
JSON object : View
Products Affected
microsoft
- java_software_development_kit
CWE
CWE-332
Insufficient Entropy in PRNG
