CVE-2026-92943 PUBLISHED

Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python

Assigner: AMZN
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store.

To remediate this issue, users should upgrade to version 1.6.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor AWS
Product AWSIoTPythonSDK
Versions Default: unaffected
  • affected from 1.5.3 to 1.6.0 (incl.)

References

Problem Types

  • CWE-297 Improper validation of certificate with host mismatch CWE

Impacts

  • CAPEC-94 Adversary in the Middle (AiTM)