hms-networks CVE Vulnerabilities & Metrics

Focus on hms-networks vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About hms-networks Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hms-networks. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hms-networks CVEs: 10
Earliest CVE date: 21 Mar 2019, 16:00 UTC
Latest CVE date: 06 Aug 2024, 14:16 UTC

Latest CVE reference: CVE-2024-33897

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 5

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hms-networks CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.67

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 3
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS hms-networks CVEs

These are the five CVEs with the highest CVSS scores for hms-networks, sorted by severity first and recency.

All CVEs for hms-networks

CVE-2024-33897 hms-networks vulnerability CVSS: 0 06 Aug 2024, 14:16 UTC

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

CVE-2024-33896 hms-networks vulnerability CVSS: 0 02 Aug 2024, 18:16 UTC

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.

CVE-2024-33893 hms-networks vulnerability CVSS: 0 02 Aug 2024, 18:16 UTC

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.

CVE-2024-33892 hms-networks vulnerability CVSS: 0 02 Aug 2024, 18:16 UTC

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

CVE-2024-6558 hms-networks vulnerability CVSS: 0 25 Jul 2024, 20:15 UTC

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host browser the next time the page is loaded, enabling social engineering attacks.

CVE-2021-33214 hms-networks vulnerability CVSS: 6.0 09 Jul 2021, 19:15 UTC

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.

CVE-2020-16230 hms-networks vulnerability CVSS: 2.1 18 Sep 2020, 19:15 UTC

All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

CVE-2020-14498 hms-networks vulnerability CVSS: 10.0 26 Aug 2020, 14:15 UTC

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

CVE-2020-10633 hms-networks vulnerability CVSS: 4.3 08 Apr 2020, 01:15 UTC

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

CVE-2018-19694 hms-networks vulnerability CVSS: 4.3 21 Mar 2019, 16:00 UTC

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.