Skip to main content

Vendor archive

hms-networks CVEs

Beta · best-effort

12 CVEs tagged to vendor hms-networks2 Critical, 3 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2024-33897

Published Aug 6, 2024

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was pa…

CVSS 9.1 · Critical

CVE-2024-33896

Published Aug 2, 2024

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in versi…

CVSS 7.2 · High

CVE-2024-33895

Published Aug 2, 2024

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and…

CVSS 6.6 · Medium

CVE-2024-33893

Published Aug 2, 2024

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixe…

CVSS 6.1 · Medium

CVE-2024-33892

Published Aug 2, 2024

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. T…

CVSS 7.5 · High

CVE-2024-6558

Published Jul 25, 2024

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTM…

CVSS 6.3 · Medium

CVE-2021-33214

Published Jul 9, 2021

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of co…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14498

Published Aug 26, 2020

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1