CRITICAL🇵🇱 Wersja polska

CVE-2023-33372

CVSS 9.8v3.1pub. 2023-08-04upd. 2024-11-21

Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices, impersonating them. in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Connectedio Connected Io

    APP
    Connectedio
    ≤ 2.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-33373CRITICAL9.8PL ✓same product

Connected IO: przechowywanie haseł i danych uwierzytelniających w postaci jawnego tekstu

CVE-2023-33374CRITICAL9.8PL ✓same product

Connected IO: zdalne wykonanie poleceń OS przez protokół zarządzający

CVE-2023-33375CRITICAL9.8PL ✓same product

Stack-based buffer overflow w protokole komunikacyjnym Connected IO

CVE-2023-33376CRITICAL9.8PL ✓same product

Argument injection w protokole iptables — Connected IO v2.1.0

CVE-2023-33377CRITICAL9.8PL ✓same product

Command Injection w Connected IO — wykonanie dowolnych poleceń przez sieć