CVE-2023-33377
Summary
| CVE | CVE-2023-33377 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-04 18:15:00 UTC |
| Updated | 2023-08-08 19:49:00 UTC |
| Description | Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Connectedio | Connected Io | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.connectedio.com/products/routers | MISC | www.connectedio.com | |
| CVE-2023-33377 | Claroty | MISC | claroty.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.