AWS News - 2025-07-17
2025-07-17
最終更新: 2026-01-17 00:23:07 JST
AI による概要
この日はセキュリティ速報が 1 件公開されました。CVE-2025-6031 として、すでにサポート終了 (2022 年 12 月 2 日に非推奨化) となった家庭用防犯カメラ Amazon Cloud Cam のデバイスペアリングに関する脆弱性が報告されました。電源投入時にデバイスがサポート終了済みのリモートサービス基盤へ接続を試み、ペアリング状態にフォールバックするため、任意のユーザーが SSL ピン留めを回避してデバイスを任意のネットワークに関連付けでき、通信の傍受・改ざんが可能になるというものです。影響を受けるバージョンは「すべて」とされています。
主要トピック
CVE-2025-6031: サポート終了済み Amazon Cloud Cam のペアリングで SSL ピン留め回避・通信傍受が可能となる脆弱性 (影響バージョン: 全て)
AWS Security Bulletins
CVE-2025-6031 - Insecure device pairing in end-of-life Amazon Cloud Cam
- Link: https://aws.amazon.com/security/security-bulletins/rss/aws-2025-013/
- Published: 2025-07-17 00:00:00
- Fetched: 2025-07-17 00:00:00
Scope: Amazon
Content Type: Informational
Publication Date: 2025/06/12 10:30 AM PDT
Description
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported.
When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due to end-of-life status. The device defaults to a pairing status in which an arbitrary user can bypass SSL pinning to associate the device to an arbitrary network, allowing for network traffic interception and modification.
Affected version: All