Логотип exploitDog
bind:CVE-2023-33374
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-33374

Количество 2

Количество 2

nvd логотип

CVE-2023-33374

больше 2 лет назад

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-jm9j-4c6r-hfr6

больше 2 лет назад

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33374

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-jm9j-4c6r-hfr6

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу