subscription which could allow an attacker to obtain sensitive
information from tapping the service communications.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1813 | The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications. |
Solution
No solution given by the vendor.
Workaround
New Rock Technologies has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of New Rock Technologies Cloud Connected Devices are invited to contact New Rock Technologies customer support https://www.newrocktech.com/ContactUs/index.html for additional information.
Thu, 30 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jan 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications. | |
| Title | New Rock Technologies Cloud Connected Devices Improper Neutralization of Wildcards or Matching Symbols | |
| Weaknesses | CWE-155 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-30T19:11:58.156Z
Reserved: 2025-01-23T16:50:56.326Z
Link: CVE-2025-0681
Updated: 2025-01-30T19:11:53.125Z
Status : Received
Published: 2025-01-30T19:15:14.300
Modified: 2025-01-30T19:15:14.300
Link: CVE-2025-0681
No data.
OpenCVE Enrichment
No data.
EUVD