Lucene search

K
zdiAnonymousZDI-21-1555
HistoryDec 21, 2021 - 12:00 a.m.

Microsoft Azure Defender for IoT sync Endpoint SQL Injection Authentication Bypass Vulnerability

2021-12-2100:00:00
Anonymous
www.zerodayinitiative.com
9

0.057 Low

EPSS

Percentile

93.4%

This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Azure Defender for IoT. Authentication is not required to exploit this vulnerability. The specific flaw exists within the sync endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system and execute arbitrary code in the context of root.

0.057 Low

EPSS

Percentile

93.4%