Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31599 Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 17:30:00 +0000

Type Values Removed Values Added
References

Tue, 03 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Hms-networks
Hms-networks ewon Cosy\+ 4g Apac
Hms-networks ewon Cosy\+ 4g Eu
Hms-networks ewon Cosy\+ 4g Jp
Hms-networks ewon Cosy\+ 4g Na
Hms-networks ewon Cosy\+ Ethernet
Hms-networks ewon Cosy\+ Firmware
Hms-networks ewon Cosy\+ Wifi
Weaknesses CWE-798
CPEs cpe:2.3:h:hms-networks:ewon_cosy\+_4g_apac:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_eu:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_jp:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_na:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_ethernet:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_wifi:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:ewon_cosy\+_firmware:*:*:*:*:*:*:*:*
Vendors & Products Hms-networks
Hms-networks ewon Cosy\+ 4g Apac
Hms-networks ewon Cosy\+ 4g Eu
Hms-networks ewon Cosy\+ 4g Jp
Hms-networks ewon Cosy\+ 4g Na
Hms-networks ewon Cosy\+ Ethernet
Hms-networks ewon Cosy\+ Firmware
Hms-networks ewon Cosy\+ Wifi
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Mon, 12 Aug 2024 15:45:00 +0000


Wed, 07 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T16:12:16.505Z

Reserved: 2024-04-28T00:00:00.000Z

Link: CVE-2024-33895

cve-icon Vulnrichment

Updated: 2024-08-07T15:27:06.739Z

cve-icon NVD

Status : Modified

Published: 2024-08-02T18:16:18.933

Modified: 2025-11-04T17:15:53.123

Link: CVE-2024-33895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.