CVE-2020-16230 Details
Description
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-20-254-03 | CVE | Third Party AdvisoryUS Government Resource |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-254-03 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hms-networks ewon flexy firmware | < 14.1 |
CPE
Remediation
| |
| hms-networks ewon flexy | All versions |
CPE
Remediation
| |
| hms-networks ewon cosy firmware | < 14.1 |
CPE
Remediation
| |
| hms-networks ewon cosy | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 22, 2021 | Reanalysis | [email protected] |
| Mar 26, 2021 | Modified Analysis | [email protected] |
| Mar 18, 2021 | CVE Modified | [email protected] |
| Mar 18, 2021 | CVE Modified | [email protected] |
| Jan 30, 2021 | Modified Analysis | [email protected] |
| Dec 23, 2020 | CVE Modified | [email protected] |
| Oct 1, 2020 | Initial Analysis | [email protected] |