CVE ID | CVE-2024-0390 |
Publication date | 15 February 2024 |
Vendor | INPRAX sp. z o.o. |
Product | iZZi connect |
Vulnerable versions | All below 2024010401 |
Vulnerability type (CWE) | Use of Hard-coded Credentials (CWE-798) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in iZZi connect application on Android and participated in its coordination. The application contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the recuperation unit "reQnet iZZi".
The weakness has been confirmed by the vendor and assigned the number CVE-2024-0390. The vulnerability was fixed in version 2024010401, released on 8th January 2024.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.