CVE-2021-40830
Last modified
CVE-2021-40830 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with access to a host’s trust stores or are able to compromise a certificate authority already in the host's trust store (note: the attacker must also be able to spoof DNS in this case) may be able to use this issue to bypass CA pinning. An attacker could then spoof the MQTT broker, and either drop traffic and/or respond with the attacker's data, but they would not be able to forward this data on to the MQTT broker because the attacker would still need the user's private keys to authenticate against the MQTT broker. The 'aws_tls_ctx_options_override_default_trust_store_*' function within the aws-c-io submodule has been updated to override the default trust store. This corrects this issue. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.5.0 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.6.1 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.12.7 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.5.3 on Linux/Unix. Amazon Web Services AWS-C-IO 0.10.4 on Linux/Unix.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Amazon Web Services Aws-C-Io | 0.10.4 |
| Amazon | Amazon Web Services Internet Of Things Device Software Development Kit V2 | < 1.5.0 |
| Amazon | Amazon Web Services Internet Of Things Device Software Development Kit V2 | < 1.5.3 |
| Amazon | Amazon Web Services Internet Of Things Device Software Development Kit V2 | < 1.6.1 |
| Amazon | Amazon Web Services Internet Of Things Device Software Development Kit V2 | < 1.12.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40830?
How severe is CVE-2021-40830?
How do I fix CVE-2021-40830?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-40825nLight ECLYPSE (nECY) system Controllers running software pr…8.6
- CVE-2021-40826Clementine Music Player through 1.3.1 is vulnerable to a Use…7.8
- CVE-2021-40827Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL…7.8
- CVE-2021-40828Connections initialized by the AWS IoT Device SDK v2 for Jav…8.8
- CVE-2021-40829Connections initialized by the AWS IoT Device SDK v2 for Jav…8.8
- CVE-2021-4083A read-after-free memory flaw was found in the Linux kernel'…7
- CVE-2021-40831The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js …7.2
- CVE-2021-40832A Denial-of-Service (DoS) vulnerability was discovered in F-…6.5
- CVE-2021-40833A vulnerability affecting F-Secure antivirus engine was disc…5.5
- CVE-2021-40834A user interface overlay vulnerability was discovered in F-s…4.3
- CVE-2021-40835An URL Address bar spoofing vulnerability was discovered in …4.3
- CVE-2021-40836A vulnerability affecting F-Secure antivirus engine was disc…5.5
Are you affected by CVE-2021-40830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
