CVE-2026-92943: CWE-297 Improper validation of certificate with host mismatch in AWS AWSIoTPythonSDK
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. To remediate this issue, users should upgrade to version 1.6.1.
AI Analysis
Technical Summary
The AWS IoT Device SDK for Python (AWSIoTPythonSDK) versions >=1.5.3 and <=1.6.0 running on Python 3.7 and later contain a CWE-297 vulnerability where the MQTT client TLS connection layer fails to validate that the server certificate matches the AWS IoT Core endpoint hostname. This flaw allows an adversary positioned as a man-in-the-middle to present a valid certificate for an unrelated hostname from the device's trust store, impersonate the AWS IoT Core endpoint, read device telemetry data, and inject arbitrary MQTT messages that the device accepts as authentic. The vulnerability affects both the default connection paths: X.509 mutual authentication on port 8883 and WebSocket with SigV4 on port 443. The port 443 ALPN path is not affected. AWS has published a security bulletin and a patch to remediate this issue.
Potential Impact
An attacker with network positioning can impersonate the AWS IoT Core endpoint by presenting a certificate for an unrelated hostname, enabling interception of sensitive telemetry data and injection of malicious MQTT messages. This compromises confidentiality, integrity, and availability of the IoT device communications. The vulnerability affects critical IoT device communication channels, potentially allowing unauthorized control or data leakage.
Mitigation Recommendations
A patch is available from AWS to fix this vulnerability. Users of AWSIoTPythonSDK versions >=1.5.3 and <=1.6.0 on Python 3.7 and later should upgrade to the fixed version as per the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/2026-114-aws/). Since this is a cloud service SDK, AWS manages the cloud infrastructure, but device-side SDK updates are required to mitigate the issue. Check the vendor advisory for the latest remediation instructions.
CVE-2026-92943: CWE-297 Improper validation of certificate with host mismatch in AWS AWSIoTPythonSDK
Description
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. To remediate this issue, users should upgrade to version 1.6.1.
CVSS v3.1
Score 8.1high
Affected software
AWS
AWSIoTPythonSDK
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The AWS IoT Device SDK for Python (AWSIoTPythonSDK) versions >=1.5.3 and <=1.6.0 running on Python 3.7 and later contain a CWE-297 vulnerability where the MQTT client TLS connection layer fails to validate that the server certificate matches the AWS IoT Core endpoint hostname. This flaw allows an adversary positioned as a man-in-the-middle to present a valid certificate for an unrelated hostname from the device's trust store, impersonate the AWS IoT Core endpoint, read device telemetry data, and inject arbitrary MQTT messages that the device accepts as authentic. The vulnerability affects both the default connection paths: X.509 mutual authentication on port 8883 and WebSocket with SigV4 on port 443. The port 443 ALPN path is not affected. AWS has published a security bulletin and a patch to remediate this issue.
Potential Impact
An attacker with network positioning can impersonate the AWS IoT Core endpoint by presenting a certificate for an unrelated hostname, enabling interception of sensitive telemetry data and injection of malicious MQTT messages. This compromises confidentiality, integrity, and availability of the IoT device communications. The vulnerability affects critical IoT device communication channels, potentially allowing unauthorized control or data leakage.
Mitigation Recommendations
A patch is available from AWS to fix this vulnerability. Users of AWSIoTPythonSDK versions >=1.5.3 and <=1.6.0 on Python 3.7 and later should upgrade to the fixed version as per the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/2026-114-aws/). Since this is a cloud service SDK, AWS manages the cloud infrastructure, but device-side SDK updates are required to mitigate the issue. Check the vendor advisory for the latest remediation instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- AMZN
- Date Reserved
- 2026-09-17T12:43:02.381Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://aws.amazon.com/security/security-bulletins/2026-114-aws/","vendor":"AWS"}]
Threat ID: 6aac405055bf5e2cf5cb2388
Added to database: 09/17/2026, 19:32:32 UTC
Last enriched: 09/17/2026, 19:45:54 UTC
Last updated: 09/18/2026, 00:31:40 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.