Record summary

CVE-2024-33896 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.

Description

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBCosy+ firmware 21.2s7 - Command InjectionExploitDB exploitby CodeB0ssNot analyzed1 file
ExploitDB

PoC details

References

6