PT-2024-25529 · Cosy+ · Cosy+

Moritz Abrell

·

Published

2024-08-02

·

Updated

2024-09-03

·

CVE-2024-33892

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cosy+ devices versions 21.x through 21.2s9 Cosy+ devices versions 22.x through 22.1s2
Description The issue concerns insecure permissions in Cosy+ devices, which can lead to information leakage through cookies. This problem is resolved in versions 21.2s10 and 22.1s3.
Recommendations For Cosy+ devices versions 21.x through 21.2s9, update to version 21.2s10 to resolve the issue. For Cosy+ devices versions 22.x through 22.1s2, update to version 22.1s3 to resolve the issue.

Exploit

Fix

Improper Preservation of Permissions

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-33892

Affected Products

Cosy+