Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31599 Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 02:30:00 +0900

Type Values Removed Values Added
References

Wed, 04 Sep 2024 04:30:00 +0900

Type Values Removed Values Added
First Time appeared Hms-networks
Hms-networks ewon Cosy\+ 4g Apac
Hms-networks ewon Cosy\+ 4g Eu
Hms-networks ewon Cosy\+ 4g Jp
Hms-networks ewon Cosy\+ 4g Na
Hms-networks ewon Cosy\+ Ethernet
Hms-networks ewon Cosy\+ Firmware
Hms-networks ewon Cosy\+ Wifi
Weaknesses CWE-798
CPEs cpe:2.3:h:hms-networks:ewon_cosy\+_4g_apac:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_eu:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_jp:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_4g_na:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_ethernet:-:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:ewon_cosy\+_wifi:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:ewon_cosy\+_firmware:*:*:*:*:*:*:*:*
Vendors & Products Hms-networks
Hms-networks ewon Cosy\+ 4g Apac
Hms-networks ewon Cosy\+ 4g Eu
Hms-networks ewon Cosy\+ 4g Jp
Hms-networks ewon Cosy\+ 4g Na
Hms-networks ewon Cosy\+ Ethernet
Hms-networks ewon Cosy\+ Firmware
Hms-networks ewon Cosy\+ Wifi
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 13 Aug 2024 00:45:00 +0900


Thu, 08 Aug 2024 01:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T16:12:16.505Z

Reserved: 2024-04-28T00:00:00.000Z

Link: CVE-2024-33895

cve-icon Vulnrichment

Updated: 2024-08-07T15:27:06.739Z

cve-icon NVD

Status : Modified

Published: 2024-08-02T18:16:18.933

Modified: 2025-11-04T17:15:53.123

Link: CVE-2024-33895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses