A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ewon_cosy+_firmware | Hms-networks | 21.0s0 (including) | 21.2s10 (excluding) |
Ewon_cosy+_firmware | Hms-networks | 22.0s0 (including) | 22.1s3 (excluding) |