CVE-2020-16230

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/09/2020
Last modified:
22/11/2021

Description

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hms-networks:ewon_flexy_firmware:*:*:*:*:*:*:*:* 14.1 (excluding)
cpe:2.3:h:hms-networks:ewon_flexy:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:ewon_cosy_firmware:*:*:*:*:*:*:*:* 14.1 (excluding)
cpe:2.3:h:hms-networks:ewon_cosy:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools