connectedio records
8 published records for vendor connectedio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-787 Out-of-bounds Write1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-33377No exploit | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, econnectedio · connected io · CWE-78 | Critical9.8 | — | 1.5% | Aug 4, 2023 |
39Monitor | CVE-2023-33374No exploit | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS cconnectedio · connected io · CWE-78 | Critical9.8 | — | 1.3% | Aug 4, 2023 |
39Monitor | CVE-2023-33375No exploit | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take contconnectedio · connected io · CWE-787 | Critical9.8 | — | 0.8% | Aug 4, 2023 |
39Monitor | CVE-2023-33378No exploit | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attaconnectedio · connected io · CWE-88 | Critical9.8 | — | 0.8% | Aug 4, 2023 |
39Monitor | CVE-2023-33376No exploit | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablinconnectedio · connected io · CWE-88 | Critical9.8 | — | 0.8% | Aug 4, 2023 |
39Monitor | CVE-2023-33372No exploit | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usiconnectedio · connected io · CWE-798 | Critical9.8 | — | 0.8% | Aug 4, 2023 |
39Monitor | CVE-2023-33379No exploit | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devicesconnectedio · er2000t-vz-cat1 firmware | Critical9.8 | — | 0.7% | Aug 4, 2023 |
39Monitor | CVE-2023-33373No exploit | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and useconnectedio · connected io · CWE-312 | Critical9.8 | — | 0.4% | Aug 4, 2023 |
- CVE-2023-3337739Monitor
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, e
CriticalCVSS 9.8No exploitEPSS 2%connectedio · connected ioAug 4, 2023
- CVE-2023-3337439Monitor
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS c
CriticalCVSS 9.8No exploitEPSS 1%connectedio · connected ioAug 4, 2023
- CVE-2023-3337539Monitor
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take cont
CriticalCVSS 9.8No exploitEPSS 1%connectedio · connected ioAug 4, 2023
- CVE-2023-3337839Monitor
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling atta
CriticalCVSS 9.8No exploitEPSS 1%connectedio · connected ioAug 4, 2023
- CVE-2023-3337639Monitor
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablin
CriticalCVSS 9.8No exploitEPSS 1%connectedio · connected ioAug 4, 2023
- CVE-2023-3337239Monitor
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usi
CriticalCVSS 9.8No exploitEPSS 1%connectedio · connected ioAug 4, 2023
- CVE-2023-3337939Monitor
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices
CriticalCVSS 9.8No exploitEPSS 1%connectedio · er2000t-vz-cat1 firmwareAug 4, 2023
- CVE-2023-3337339Monitor
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use
CriticalCVSS 9.8No exploitEPSS 0%connectedio · connected ioAug 4, 2023