Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://www.connectedio.com/products/routers | product |
https://claroty.com/team82/disclosure-dashboard/cve-2023-33373 | third party advisory |