CVE-2024-33897

CRITICAL

HMS Networks ewon Cosy+ Firmware >=21.0s0 <21.2s10 - Availability Issue via Certificate Signing Request

Title source: llm
STIX 2.1

Description

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

Scores

CVSS v3 9.1
EPSS 0.0066
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (1)
hms-networks/ewon_cosy\+_firmware 21.0s0 - 21.2s10
Published Aug 06, 2024
Tracked Since Feb 18, 2026