CVE Vulnerabilities

CVE-2024-33897

Direct Request ('Forced Browsing')

Published: Aug 06, 2024 | Modified: Aug 12, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Ewon_cosy+_firmware Hms-networks 21.0s0 (including) 21.2s10 (excluding)
Ewon_cosy+_firmware Hms-networks 22.0s0 (including) 22.1s3 (excluding)

Potential Mitigations

References