SonarSource / argument-injection-vectors

A curated list of argument injection vectors
GNU General Public License v3.0
37 stars 3 forks source link

Investigate CVE-2023-33376 and CVE-2023-33378 on ConnectedIO #18

Open thomas-chauchefoin-sonarsource opened 1 year ago

thomas-chauchefoin-sonarsource commented 1 year ago

Two argument injections were found on ConnectedIO <= v2.1.0, on the "AT command message" and "ip tables command message". The advisories say they both led to RCE, so it's worth investigating to find potential new vectors.