Back to search
CVE-2024-0390
Published: Feb 15, 2024
Modified: Mar 13, 2025
PUBLISHED
Description
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the recuperation unit "reQnet iZZi".This issue affects "iZZi connect" application versions before 2024010401.
| Vendor | Product | Versions |
|---|---|---|
INPRAX | iZZi connect | affected 0 - < 2024010401 |
Weaknesses (CWE)
References
https://cert.pl/en/posts/2024/02/CVE-2024-0390/
third-party-advisory
https://cert.pl/posts/2024/02/CVE-2024-0390/
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now