A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-08-06 14:16
Updated : 2024-11-21 09:17
NVD link : CVE-2024-33897
Mitre link : CVE-2024-33897
CVE.ORG link : CVE-2024-33897
JSON object : View
Products Affected
hms-networks
- ewon_cosy\+_4g_na
- ewon_cosy\+_4g_apac
- ewon_cosy\+_4g_eu
- ewon_cosy\+_ethernet
- ewon_cosy\+_4g_jp
- ewon_cosy\+_firmware
- ewon_cosy\+_wifi
CWE
CWE-425
Direct Request ('Forced Browsing')