CVE-2024-33893
02.08.2024, 18:16
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
| Vendor | Product | Version |
|---|---|---|
| hms-networks | ewon_cosy\+_firmware | 21.0 ≤ 𝑥 ≤ 21.2s10 |
| hms-networks | ewon_cosy\+_firmware | 22.0 ≤ 𝑥 ≤ 22.1s3 |
𝑥
= Vulnerable software versions
References