Description
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store.



To remediate this issue, users should upgrade to version 1.6.1.
Published: 2026-09-17
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Interception and manipulation of MQTT traffic
Action: Immediate Patch
AI Analysis

Impact

An attacker with a man‑in‑the‑middle position can present a TLS certificate for any hostname that is trusted by the device’s trust store. Because the AWS IoT Device SDK for Python versions 1.5.3 through 1.6.0 does not verify that the certificate’s hostname matches the AWS IoT Core endpoint, the MQTT client accepts the connection, allowing the attacker to impersonate the endpoint, read telemetry, and inject arbitrary MQTT messages that the device processes as if they were authentic. This flaw is an improper validation weakness (CWE‑297).

Affected Systems

Vendor: Amazon Web Services. Product: AWS IoT Device SDK for Python. Affected releases are 1.5.3 up to and including 1.6.0 for Python 3.7 and later. All deployments that use these versions of the SDK in an IoT device telemetry or command pipeline are potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity. The EPSS score of less than 1 % shows that exploitation probability is low, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the attack requires only the ability to place a TLS certificate issued by a CA present in the device’s trust store and to interfere with network traffic to the legitimate AWS IoT Core endpoint, conditions that are common in compromised or mis‑configured deployments. An attacker could easily read or tamper with device data without detection, resulting in confidentiality and integrity compromise for all data flowing through that device.

Generated by OpenCVE AI on September 19, 2026 at 06:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AWS IoT Device SDK for Python to v1.6.1 or later on all devices.
  • Update deployment and configuration management tools to install the patched SDK version on all existing devices, ensuring that no legacy installations remain.
  • Enable hostname verification in the MQTT client TLS configuration to enforce that the certificate presented by the server matches the AWS IoT Core endpoint, removing the possibility of a host‑name mismatch acceptance.

Generated by OpenCVE AI on September 19, 2026 at 06:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. To remediate this issue, users should upgrade to version 1.6.1.
Title Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
First Time appeared Aws
Aws awsiotpythonsdk
Weaknesses CWE-297
CPEs cpe:2.3:a:aws:awsiotpythonsdk:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws awsiotpythonsdk
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Aws Awsiotpythonsdk
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-17T19:57:09.515Z

Reserved: 2026-09-17T12:43:02.381Z

Link: CVE-2026-92943

cve-icon Vulnrichment

Updated: 2026-09-17T19:57:01.778Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T20:18:59.333

Modified: 2026-09-18T17:48:19.003

Link: CVE-2026-92943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:15:17Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch