CVE-2024-33895 affects HMS Networks Ewon Cosy+ devices running firmware versions 21.x below 21.2s10 or 22.x below 22.1s3. The vulnerability, rated Medium (CVSS 6.6), stems from the use of a non-unique encryption key for configuration parameters, allowing an attacker with physical access (AV:P) to potentially compromise confidentiality, integrity, and availability (C:H/I:H/A:H) with low attack complexity (AC:L). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue has been remediated in firmware versions 21.2s10 and 22.1s3, where a unique key is now generated per device.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21.0, <= 21.2s10CPE matchmatch criteria | cpe:2.3:o:hms-networks:ewon_cosy\+_firmware:*:*:*:*:*:*:*:* | ||
>= 22.0, <= 22.1s3CPE matchmatch criteria | cpe:2.3:o:hms-networks:ewon_cosy\+_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.