Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
New Rock Technologies has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of New Rock Technologies Cloud Connected Devices are invited to contact New Rock Technologies customer supportĀ for additional information.
Thu, 30 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 30 Jan 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud. | |
Title | New Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-30T19:15:29.817Z
Reserved: 2025-01-23T16:50:54.661Z
Link: CVE-2025-0680

Updated: 2025-01-30T19:15:25.771Z

Status : Received
Published: 2025-01-30T19:15:14.147
Modified: 2025-01-30T19:15:14.147
Link: CVE-2025-0680

No data.

No data.