CVE Vulnerabilities

CVE-2024-33894

Improper Privilege Management

Published: Aug 02, 2024 | Modified: Jun 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Ewon_cosy+_firmwareHms-networks21.0s0 (including)21.2s10 (excluding)
Ewon_cosy+_firmwareHms-networks22.0s0 (including)22.1s3 (excluding)

Potential Mitigations

References