Description
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37536 | Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices. |
References
History
Thu, 17 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T15:33:01.497Z
Reserved: 2023-05-22T00:00:00.000Z
Link: CVE-2023-33373
Updated: 2024-08-02T15:47:05.688Z
Status : Modified
Published: 2023-08-04T18:15:12.050
Modified: 2024-11-21T08:05:30.113
Link: CVE-2023-33373
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD