Impact
An attacker with a man‑in‑the‑middle position can present a TLS certificate for any hostname that is trusted by the device’s trust store. Because the AWS IoT Device SDK for Python versions 1.5.3 through 1.6.0 does not verify that the certificate’s hostname matches the AWS IoT Core endpoint, the MQTT client accepts the connection, allowing the attacker to impersonate the endpoint, read telemetry, and inject arbitrary MQTT messages that the device processes as if they were authentic. This flaw is an improper validation weakness (CWE‑297).
Affected Systems
Vendor: Amazon Web Services. Product: AWS IoT Device SDK for Python. Affected releases are 1.5.3 up to and including 1.6.0 for Python 3.7 and later. All deployments that use these versions of the SDK in an IoT device telemetry or command pipeline are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity. The EPSS score of less than 1 % shows that exploitation probability is low, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the attack requires only the ability to place a TLS certificate issued by a CA present in the device’s trust store and to interfere with network traffic to the legitimate AWS IoT Core endpoint, conditions that are common in compromised or mis‑configured deployments. An attacker could easily read or tamper with device data without detection, resulting in confidentiality and integrity compromise for all data flowing through that device.
OpenCVE Enrichment