{"api_version":"1","generated_at":"2026-07-23T20:14:11+00:00","cve":"CVE-2023-33377","urls":{"html":"https://cve.report/CVE-2023-33377","api":"https://cve.report/api/cve/CVE-2023-33377.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-33377","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-33377"},"summary":{"title":"CVE-2023-33377","description":"Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-08-04 18:15:00","updated_at":"2023-08-08 19:49:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://www.connectedio.com/products/routers","name":"https://www.connectedio.com/products/routers","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://claroty.com/team82/disclosure-dashboard/cve-2023-33377","name":"https://claroty.com/team82/disclosure-dashboard/cve-2023-33377","refsource":"MISC","tags":[],"title":"CVE-2023-33377 | Claroty","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-33377","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33377","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"33377","vulnerable":"1","versionEndIncluding":"2.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"connectedio","cpe5":"connected_io","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2023-33377","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.connectedio.com/products/routers","refsource":"MISC","name":"https://www.connectedio.com/products/routers"},{"refsource":"MISC","name":"https://claroty.com/team82/disclosure-dashboard/cve-2023-33377","url":"https://claroty.com/team82/disclosure-dashboard/cve-2023-33377"}]}},"nvd":{"publishedDate":"2023-08-04 18:15:00","lastModifiedDate":"2023-08-08 19:49:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:connectedio:connected_io:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}