PT-2024-25531 · Cosy+ · Cosy+

Moritz Abrell

·

Published

2024-08-02

·

Updated

2024-08-18

·

CVE-2024-33894

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cosy+ devices versions 21.x below 21.2s10 Cosy+ devices versions 22.x below 22.1s3
Description The issue is related to insecure permissions, where several processes are executed with elevated privileges. This is an example of Execution with Unnecessary Privileges.
Recommendations For Cosy+ devices versions 21.x below 21.2s10, update to version 21.2s10 or later to resolve the issue. For Cosy+ devices versions 22.x below 22.1s3, update to version 22.1s3 or later to resolve the issue.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-33894

Affected Products

Cosy+