Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37541 | Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T15:28:54.358Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33378
Updated: 2024-08-02T15:47:05.246Z
Status : Modified
Published: 2023-08-04T18:15:12.783
Modified: 2024-11-21T08:05:30.973
Link: CVE-2023-33378
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD