Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) (CWE-78) CVE-2024-33896

Read Time:19 Second

Posted by Moritz Abrell via Fulldisclosure on Aug 17

Advisory ID: SYSS-2024-018
Product: Ewon Cosy+
Manufacturer: HMS Industrial Networks AB
Affected Version(s): Firmware Versions: < 21.2s10 and < 22.1s3
Tested Version(s): Firmware Version: 21.2s7
Vulnerability Type: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
(CWE-78)
Risk Level: Medium
Solution Status:…

Read More