SB2020091116 - Overly permissive cross-domain whitelist in HMS Networks Ewon Flexy and Cosy



SB2020091116 - Overly permissive cross-domain whitelist in HMS Networks Ewon Flexy and Cosy

Published: September 11, 2020

Security Bulletin ID SB2020091116
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Overly permissive cross-domain whitelist (CVE-ID: CVE-2020-16230)

The vulnerability allows a local user to bypass the CORS protection mechanism.

The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A local administrator can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and retrieve limited confidential information through sniffing.


Remediation

Install update from vendor's website.