Записи connectedio
8 опубликованных записей вендора connectedio.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-787 Out-of-bounds Write1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-33377Эксплойта нет | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, econnectedio · connected io · CWE-78 | Критическая9,8 | — | 1,5 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33374Эксплойта нет | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS cconnectedio · connected io · CWE-78 | Критическая9,8 | — | 1,3 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33375Эксплойта нет | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take contconnectedio · connected io · CWE-787 | Критическая9,8 | — | 0,8 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33378Эксплойта нет | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attaconnectedio · connected io · CWE-88 | Критическая9,8 | — | 0,8 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33376Эксплойта нет | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablinconnectedio · connected io · CWE-88 | Критическая9,8 | — | 0,8 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33372Эксплойта нет | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usiconnectedio · connected io · CWE-798 | Критическая9,8 | — | 0,8 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33379Эксплойта нет | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devicesconnectedio · er2000t-vz-cat1 firmware | Критическая9,8 | — | 0,7 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-33373Эксплойта нет | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and useconnectedio · connected io · CWE-312 | Критическая9,8 | — | 0,4 % | 4 авг. 2023 г. |
- CVE-2023-3337739Наблюдать
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, e
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337439Наблюдать
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337539Наблюдать
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take cont
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337839Наблюдать
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling atta
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337639Наблюдать
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337239Наблюдать
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · connected io4 авг. 2023 г.
- CVE-2023-3337939Наблюдать
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectedio · er2000t-vz-cat1 firmware4 авг. 2023 г.
- CVE-2023-3337339Наблюдать
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %connectedio · connected io4 авг. 2023 г.