CVE Vulnerabilities

CVE-2024-33897

Direct Request ('Forced Browsing')

Published: Aug 06, 2024 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Ewon_cosy+_firmwareHms-networks21.0s0 (including)21.2s10 (excluding)
Ewon_cosy+_firmwareHms-networks22.0s0 (including)22.1s3 (excluding)

Potential Mitigations

References