CVE Vulnerabilities

CVE-2024-33894

Improper Privilege Management

Published: Aug 02, 2024 | Modified: Jun 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Ewon_cosy+_firmware Hms-networks 21.0s0 (including) 21.2s10 (excluding)
Ewon_cosy+_firmware Hms-networks 22.0s0 (including) 22.1s3 (excluding)

Potential Mitigations

References