Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-33379

Опубликовано: 04 авг. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:connectedio:er2000t-vz-cat1_firmware:*:*:*:*:*:*:*:*
Версия до 2.1.0 (включая)
cpe:2.3:h:connectedio:er2000t-vz-cat1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

NVD-CWE-noinfo