Description
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
References (6)
Scores
CVSS v3
9.1
EPSS
0.0053
EPSS Percentile
67.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-425
Status
published
Products (1)
hms-networks/ewon_cosy\+_firmware
21.0s0 - 21.2s10
Published
Aug 06, 2024
Tracked Since
Feb 18, 2026