PT-2024-25534 · Hms Networks · Hms Networks Cosy+

Moritz Abrell

·

Published

2024-08-06

·

Updated

2024-10-10

·

CVE-2024-33897

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions HMS Networks Cosy+ (affected versions not specified)
Description The issue concerns improper authentication, allowing a compromised device to request a Certificate Signing Request for another device, potentially leading to an availability issue. This could enable local network attacks due to improper certificate validation. The problem was patched on the Talk2m production server on April 18, 2024.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-33897

Affected Products

Hms Networks Cosy+