In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
References
Link | Resource |
---|---|
https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcher | Vendor Advisory |
https://labs.bishopfox.com/advisories | Third Party Advisory |
https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4 | Vendor Advisory |
https://www.ewon.biz/about-us/security | Vendor Advisory |
https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-07-09 12:15
Updated : 2021-09-21 09:33
NVD link : CVE-2021-33214
Mitre link : CVE-2021-33214
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
hms-networks
- ecatcher