PT-2024-39458 · Hms Networks · Ewon Flexy 205

T. Fankhauser

+1

·

Published

2024-12-19

·

Updated

2024-12-22

·

CVE-2024-9154

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ewon Flexy 205 versions through 14.8s0
Description A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device.
Recommendations For Ewon Flexy 205 versions through 14.8s0, update to a version later than 14.8s0 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-9154

Affected Products

Ewon Flexy 205