CVE-2024-33892
02.08.2024, 18:16
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3Enginsight
Vendor | Product | Version |
---|---|---|
hms-networks | ewon_cosy\+_firmware | 21.0s0 ≤ 𝑥 < 21.2s10 |
hms-networks | ewon_cosy\+_firmware | 22.0s0 ≤ 𝑥 < 22.1s3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
- CWE-281 - Improper Preservation of PermissionsThe software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
References