Connectedio

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 8
    Known Exploited: 0
    8
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-33372

    Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices, impersonating them. in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2023

    CVE-2023-33373

    Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2023

    CVE-2023-33374

    Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2023

    CVE-2023-33375

    Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2023

    CVE-2023-33376

    Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2023
    Items Per Page
    Connectedio Vulnerabilities & Security CVEs | CVE-DB