Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-33897
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
0
Attacker Value
Unknown
CVE-2024-33896
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
0
Attacker Value
Unknown
CVE-2024-33895
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
0
Attacker Value
Unknown
CVE-2024-33893
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
0
Attacker Value
Unknown
CVE-2024-33892
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
0
Attacker Value
Unknown
CVE-2020-16230
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.
0
Attacker Value
Unknown
CVE-2020-10633
Disclosure Date: April 08, 2020 (last updated February 21, 2025)
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.
0