Перейти к содержимому
Noroxi

Записи connectedio

8 опубликованных записей вендора connectedio.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

8 записей
  • CVE-2023-33377
    39Наблюдать

    Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, e

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33374
    39Наблюдать

    Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS c

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33375
    39Наблюдать

    Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take cont

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33378
    39Наблюдать

    Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling atta

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33376
    39Наблюдать

    Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablin

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33372
    39Наблюдать

    Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usi

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · connected io4 авг. 2023 г.

  • CVE-2023-33379
    39Наблюдать

    Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectedio · er2000t-vz-cat1 firmware4 авг. 2023 г.

  • CVE-2023-33373
    39Наблюдать

    Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    connectedio · connected io4 авг. 2023 г.