CVE-2024-33895

MEDIUM

Ewon Cosy+ Firmware 21.x < 21.2s10 and 22.x < 22.1s3 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

Scores

CVSS v3 6.6
EPSS 0.0050
EPSS Percentile 38.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
hms-networks/ewon_cosy\+_firmware 21.0 - 21.2s10
Published Aug 02, 2024
Tracked Since Feb 18, 2026