connectedio kayıtları
connectedio üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-787 Out-of-bounds Write1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-33377İstismar yok | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, econnectedio · connected io · CWE-78 | Kritik9,8 | — | %1,5 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33374İstismar yok | Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS cconnectedio · connected io · CWE-78 | Kritik9,8 | — | %1,3 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33375İstismar yok | Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take contconnectedio · connected io · CWE-787 | Kritik9,8 | — | %0,8 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33378İstismar yok | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attaconnectedio · connected io · CWE-88 | Kritik9,8 | — | %0,8 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33376İstismar yok | Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablinconnectedio · connected io · CWE-88 | Kritik9,8 | — | %0,8 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33372İstismar yok | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usiconnectedio · connected io · CWE-798 | Kritik9,8 | — | %0,8 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33379İstismar yok | Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devicesconnectedio · er2000t-vz-cat1 firmware | Kritik9,8 | — | %0,7 | 4 Ağu 2023 |
39İzleyin | CVE-2023-33373İstismar yok | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and useconnectedio · connected io · CWE-312 | Kritik9,8 | — | %0,4 | 4 Ağu 2023 |
- CVE-2023-3337739İzleyin
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, e
KritikCVSS 9,8İstismar yokEPSS %2connectedio · connected io4 Ağu 2023
- CVE-2023-3337439İzleyin
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS c
KritikCVSS 9,8İstismar yokEPSS %1connectedio · connected io4 Ağu 2023
- CVE-2023-3337539İzleyin
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take cont
KritikCVSS 9,8İstismar yokEPSS %1connectedio · connected io4 Ağu 2023
- CVE-2023-3337839İzleyin
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling atta
KritikCVSS 9,8İstismar yokEPSS %1connectedio · connected io4 Ağu 2023
- CVE-2023-3337639İzleyin
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enablin
KritikCVSS 9,8İstismar yokEPSS %1connectedio · connected io4 Ağu 2023
- CVE-2023-3337239İzleyin
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication usi
KritikCVSS 9,8İstismar yokEPSS %1connectedio · connected io4 Ağu 2023
- CVE-2023-3337939İzleyin
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices
KritikCVSS 9,8İstismar yokEPSS %1connectedio · er2000t-vz-cat1 firmware4 Ağu 2023
- CVE-2023-3337339İzleyin
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use
KritikCVSS 9,8İstismar yokEPSS %0connectedio · connected io4 Ağu 2023