Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2023
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-08-04
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-08-04
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
CVSS Score
6.5
EPSS Score
0.015
Published
2023-08-04
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.
CVSS Score
9.8
EPSS Score
0.0
Published
2023-08-04
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution.
CVSS Score
9.8
EPSS Score
0.013
Published
2023-08-04
Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-08-04
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-08-04
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
CVSS Score
9.8
EPSS Score
0.004
Published
2023-08-04
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-08-04
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-08-04


Contact Us

Shodan ® - All rights reserved