Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ewon Cosy\+ Firmware CRITICAL 9.1
CVE-2024-33897

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availa…

Fix: 21.2s10 / 22.1s3+
Fix from $2,300 2024-08-06
Ewon Cosy\+ Firmware HIGH 7.2
CVE-2024-33896

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blackl…

Fix: after 22.1s3
Fix from $1,950 2024-08-02
Ewon Cosy\+ Firmware HIGH 8.8
CVE-2024-33894

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several proces…

Fix: 21.2s10 / 22.1s3+
Fix from $1,950 2024-08-02
Ewon Cosy\+ Firmware HIGH 7.5
CVE-2024-33892

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking …

Fix: 21.2s10 / 22.1s3+
Fix from $1,950 2024-08-02
Ewon Cosy\+ Firmware MEDIUM 6.6
CVE-2024-33895

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is…

Fix: after 22.1s3
Fix from $1,600 2024-08-02
Ewon Cosy\+ Firmware MEDIUM 6.1
CVE-2024-33893

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper in…

Fix: after 22.1s3
Fix from $1,600 2024-08-02
Anybus Compactcom 30 Module Ethernet\/ip Firmware MEDIUM 6.1
CVE-2024-6558

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence…

Mitigation only
Fix from $1,600 2024-07-25
Ecatcher MEDIUM 6.1
CVE-2021-33214

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information …

Fix: after 6.6.4
Fix from $1,600 2021-07-09
Ecatcher CRITICAL 10.0
CVE-2020-14498

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remote…

Fix: 6.5.5+
Fix from $2,300 2020-08-26
Ewon Flexy Firmware MEDIUM 6.1
CVE-2020-10633

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could se…

Fix: 14.1s0+
Fix from $1,600 2020-04-08
Netbiter Ws100 Firmware MEDIUM 6.1
CVE-2018-19694

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

Fix: after 3.30.5
Fix from $1,600 2019-03-21