CVE-2026-21528
Analyzed
Analyzed - Analysis Complete
Information Disclosure via Unrestricted IP Binding in Azure IoT SDK
Publication date: 2026-02-10
Last updated on: 2026-02-19
Assigner: Microsoft Corporation
Description
Description
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | azure_iot_explorer | to 0.15.13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-668 | The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. |
| CWE-1327 | The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely. |