Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ewon_cosy+_firmware | Hms-networks | 21.0s0 (including) | 21.2s10 (excluding) |
Ewon_cosy+_firmware | Hms-networks | 22.0s0 (including) | 22.1s3 (excluding) |