Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-08-04T00:00:00

Updated: 2024-08-02T15:47:05.195Z

Reserved: 2023-05-22T00:00:00

Link: CVE-2023-33379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-08-04T18:15:12.937

Modified: 2023-08-10T15:34:55.840

Link: CVE-2023-33379

cve-icon Redhat

No data.