Fiche vulnérabilité
CVE-2023-33376 : faille critique connectedio connected io (CVSS 9.8)
Description
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 4 août 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- connectedio connected io