Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 31 Oct 2024 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
Tue, 03 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hms-networks
Hms-networks ewon Cosy\+ 4g Apac Hms-networks ewon Cosy\+ 4g Eu Hms-networks ewon Cosy\+ 4g Jp Hms-networks ewon Cosy\+ 4g Na Hms-networks ewon Cosy\+ Ethernet Hms-networks ewon Cosy\+ Firmware Hms-networks ewon Cosy\+ Wifi |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:h:hms-networks:ewon_cosy\+_4g_apac:-:*:*:*:*:*:*:* cpe:2.3:h:hms-networks:ewon_cosy\+_4g_eu:-:*:*:*:*:*:*:* cpe:2.3:h:hms-networks:ewon_cosy\+_4g_jp:-:*:*:*:*:*:*:* cpe:2.3:h:hms-networks:ewon_cosy\+_4g_na:-:*:*:*:*:*:*:* cpe:2.3:h:hms-networks:ewon_cosy\+_ethernet:-:*:*:*:*:*:*:* cpe:2.3:h:hms-networks:ewon_cosy\+_wifi:-:*:*:*:*:*:*:* cpe:2.3:o:hms-networks:ewon_cosy\+_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Hms-networks
Hms-networks ewon Cosy\+ 4g Apac Hms-networks ewon Cosy\+ 4g Eu Hms-networks ewon Cosy\+ 4g Jp Hms-networks ewon Cosy\+ 4g Na Hms-networks ewon Cosy\+ Ethernet Hms-networks ewon Cosy\+ Firmware Hms-networks ewon Cosy\+ Wifi |
|
Metrics |
cvssV3_1
|
Sun, 18 Aug 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
ssvc
|
Mon, 12 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-08-02T00:00:00
Updated: 2024-10-30T19:18:21.436Z
Reserved: 2024-04-28T00:00:00
Link: CVE-2024-33893
Vulnrichment
Updated: 2024-08-18T08:02:59.637Z
NVD
Status : Modified
Published: 2024-08-02T18:16:18.743
Modified: 2024-11-21T09:17:40.830
Link: CVE-2024-33893
Redhat
No data.