Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2025-0432
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.
0
Attacker Value
Unknown
CVE-2024-9154
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).
0
Attacker Value
Unknown
CVE-2024-7755
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.
0
Attacker Value
Unknown
CVE-2024-33897
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
0
Attacker Value
Unknown
CVE-2024-33896
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
0
Attacker Value
Unknown
CVE-2024-33895
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
0
Attacker Value
Unknown
CVE-2024-33893
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
0
Attacker Value
Unknown
CVE-2024-33892
Disclosure Date: August 02, 2024 (last updated September 04, 2024)
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
0
Attacker Value
Unknown
CVE-2024-6558
Disclosure Date: July 25, 2024 (last updated August 14, 2024)
HMS Industrial Networks
Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host browser the next time the page is loaded, enabling social engineering attacks.
0
Attacker Value
Unknown
CVE-2021-33214
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
0