CVE-2024-33892
HIGHDescription
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3
Is your site exposed to CVE-2024-33892?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hms-networks | ewon_cosy\+_firmware |
| hms-networks | ewon_cosy\+_firmware |
| hms-networks | ewon_cosy\+_4g_apac |
| hms-networks | ewon_cosy\+_4g_eu |
| hms-networks | ewon_cosy\+_4g_jp |
| hms-networks | ewon_cosy\+_4g_na |
| hms-networks | ewon_cosy\+_ethernet |
| hms-networks | ewon_cosy\+_wifi |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-33892? +
How severe is CVE-2024-33892? +
What products are affected by CVE-2024-33892? +
How do I check if I'm vulnerable to CVE-2024-33892? +
Related Vulnerabilities
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token …
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows …
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker …
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of …
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are …
This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An …