← back
CVE-2024-0390

Hard-coded credentials in iZZi connect application

CVSS 6.2 MEDIUMEPSS 0.4%CWE-798
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.2EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the recuperation unit "reQnet iZZi".This issue affects "iZZi connect" application versions before 2024010401.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
INPRAX · iZZi connect

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →