ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-33897
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issu

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

NVD description · AI analysis pending
9.1<1% PoC
  • hms-networks ewon cosy\+ firmware
CVE-2024-33894
+4 in the same advisory: …33892 …33896 …33895 …33893
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with el

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

NVD description · AI analysis pending
8.8
group max
<1% PoC ×2
  • hms-networks ewon cosy\+ firmware
CVE-2024-6558
HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks.

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host browser the next time the page is loaded, enabling social engineering attacks.

NVD description · AI analysis pending
6.3<1%
  • hms-networks anybus compactcom 30 module ethernet\/ip firmware
  • hms-networks anybus compactcom 30 module usb without housing firmware
CVE-2021-33214
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure,

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.

NVD description · AI analysis pending
6.1<1% PoC
  • hms-networks ecatcher
CVE-2020-16230
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources.

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

NVD description · AI analysis pending
2.3<1%
  • hms-networks ewon flexy firmware
  • hms-networks ewon cosy firmware
CVE-2020-14498
HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

NVD description · AI analysis pending
10.03%
  • hms-networks ecatcher
CVE-2020-10633
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0).

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

NVD description · AI analysis pending
6.1<1%
  • hms-networks ewon flexy firmware
  • hms-networks ewon cosy firmware
CVE-2018-19694
HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

NVD description · AI analysis pending
6.12% PoC ×2
  • hms-networks netbiter ws100 firmware
  • hms-networks netbiter ws200 firmware
  • hms-networks netbiter ec150 firmware
  • +1 more