In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
References
Link | Resource |
---|---|
https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4 | Vendor Advisory |
https://labs.bishopfox.com/advisories | Third Party Advisory |
https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4 | Exploit Third Party Advisory |
https://www.ewon.biz/about-us/security | Vendor Advisory |
https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcher | Vendor Advisory |
https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4 | Vendor Advisory |
https://labs.bishopfox.com/advisories | Third Party Advisory |
https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4 | Exploit Third Party Advisory |
https://www.ewon.biz/about-us/security | Vendor Advisory |
https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcher | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4 - Vendor Advisory | |
References | () https://labs.bishopfox.com/advisories - Third Party Advisory | |
References | () https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4 - Exploit, Third Party Advisory | |
References | () https://www.ewon.biz/about-us/security - Vendor Advisory | |
References | () https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcher - Vendor Advisory |
Information
Published : 2021-07-09 19:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33214
Mitre link : CVE-2021-33214
CVE.ORG link : CVE-2021-33214
JSON object : View
Products Affected
hms-networks
- ecatcher
CWE
CWE-276
Incorrect Default Permissions