Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-37542 Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Connectedio connected Io
CPEs cpe:2.3:a:connectedio:connected_io:*:*:*:*:*:*:*:*
Vendors & Products Connectedio connected Io
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-17T15:16:20.577Z

Reserved: 2023-05-22T00:00:00

Link: CVE-2023-33379

cve-icon Vulnrichment

Updated: 2024-08-02T15:47:05.195Z

cve-icon NVD

Status : Modified

Published: 2023-08-04T18:15:12.937

Modified: 2024-11-21T08:05:31.147

Link: CVE-2023-33379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses