Report an incident
Report an incident

Vulnerability in iZZi connect application
15 February 2024 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2024-0390
Publication date 15 February 2024
Vendor INPRAX sp. z o.o.
Product iZZi connect
Vulnerable versions All below 2024010401
Vulnerability type (CWE) Use of Hard-coded Credentials (CWE-798)
Report source Report to CERT Polska

Description

CERT Polska has received a report about vulnerability in iZZi connect application on Android and participated in its coordination. The application contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the recuperation unit "reQnet iZZi".

The weakness has been confirmed by the vendor and assigned the number CVE-2024-0390. The vulnerability was fixed in version 2024010401, released on 8th January 2024.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.