Vulnerabilities > HMS Networks

DATE CVE VULNERABILITY TITLE RISK
2021-07-09 CVE-2021-33214 Incorrect Default Permissions vulnerability in Hms-Networks Ecatcher
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
6.0
2020-09-18 CVE-2020-16230 Unspecified vulnerability in Hms-Networks Ewon Cosy Firmware and Ewon Flexy Firmware
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources.
local
low complexity
hms-networks
2.1
2020-08-26 CVE-2020-14498 Out-of-bounds Write vulnerability in Hms-Networks Ecatcher
HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
network
low complexity
hms-networks CWE-787
critical
10.0
2020-04-08 CVE-2020-10633 Cross-site Scripting vulnerability in Hms-Networks Ewon Cosy Firmware and Ewon Flexy Firmware
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0).
4.3
2019-03-21 CVE-2018-19694 Cross-site Scripting vulnerability in Hms-Networks products
HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
4.3