seclists.org
http://seclists.org/fulldisclosure/2024/Aug/21 CVE-2024-33896
HIGH
Cosy+ firmware 21.2s7 - Command Injection
Record summary
CVE-2024-33896 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBCosy+ firmware 21.2s7 - Command InjectionExploitDB exploitby CodeB0ssNot analyzed1 file
References
6blog.syss.com
https://blog.syss.com/posts/hacking-a-secure-industrial-remote-access-gateway hmsnetworks.blob.core.windows.net
https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/cybersecurity/security-advisory/hms-security-advisory-2024-07-29-001--ewon-several-cosy--vulnerabilities.pdf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33896 ewon.biz
https://www.ewon.biz/products/cosy/ewon-cosy-wifi hms-networks.com
https://www.hms-networks.com/cyber-security