Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connected Io CRITICAL 9.8
CVE-2023-33373

Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to …

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33374

Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands f…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33375

Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over …

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33376

Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attacke…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33377

Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling a…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33378

Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to …

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Er2000t Vz Cat1 Firmware CRITICAL 9.8
CVE-2023-33379

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to conne…

Fix: after 2.1.0
Fix from $2,300 2023-08-04
Connected Io CRITICAL 9.8
CVE-2023-33372

Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. …

Fix: after 2.1.0
Fix from $2,300 2023-08-04