SentinelLabs disclosed multiple critical vulnerabilities in Microsoft Azure Defender for IoT that affected both cloud-connected and on-premises deployments and could allow attackers to compromise appliances without authentication. The issues included weaknesses in the password recovery workflow, such as a time-of-check/time-of-use race condition and logic flaws in certificate and subscription validation, tracked in part as CVE-2021-42310, which could let an attacker reset privileged passwords and take over administrative accounts.
The report also detailed a command injection flaw that could lead to root remote code execution after account takeover (CVE-2021-42312), unauthenticated SQL injection bugs in token-related endpoints that could expose session IDs and enable further compromise (CVE-2021-42313 and CVE-2021-42311), and a heap-based buffer overflow in the RCDCAP traffic-processing component (CVE-2021-37222). Microsoft issued security updates and advisories after responsible disclosure, and SentinelLabs said it had not observed active exploitation in the wild at the time of publication.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued security updates and advisories in December 2021 to address the reported Azure Defender for IoT vulnerabilities affecting cloud-connected and on-premises deployments. The fixes covered flaws including unauthorized password reset, command injection, SQL injection, and a buffer overflow.
SentinelLabs discovered multiple critical vulnerabilities in Microsoft Azure Defender for IoT and proactively disclosed them to Microsoft. The issues were later tracked as CVE-2021-42310, CVE-2021-42312, CVE-2021-37222, CVE-2021-42313, and CVE-2021-42311.
SentinelLabs published technical details on multiple critical Azure Defender for IoT flaws, including password recovery logic issues, command injection, unauthenticated SQL injection, and a heap-based buffer overflow. At the time of publication, SentinelLabs said it had not observed in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.