CVE-2023-33379
Last modified
CVE-2023-33379 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Connectedio | Er2000t-Vz-Cat1 Firmware | <= 2.1.0 |
References
- https://claroty.com/team82/disclosure-dashboard/cve-2023-33379Third Party Advisory
- https://claroty.com/team82/disclosure-dashboard/cve-2023-33379Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33379?
How severe is CVE-2023-33379?
How do I fix CVE-2023-33379?
Are you affected by CVE-2023-33379?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
