VulnerabilityModified
CVE-2021-33214
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
MEDIUM 6.1EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- hms-networks/ecatcher
- Source
- cve@mitre.org
References
- https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4Vendor Advisory
- https://labs.bishopfox.com/advisoriesThird Party Advisory
- https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4Exploit, Third Party Advisory
- https://www.ewon.biz/about-us/securityVendor Advisory
- https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcherVendor Advisory
- https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4Vendor Advisory
- https://labs.bishopfox.com/advisoriesThird Party Advisory
- https://labs.bishopfox.com/advisories/ecatcher-desktop-version-6.6.4Exploit, Third Party Advisory
- https://www.ewon.biz/about-us/securityVendor Advisory
- https://www.ewon.biz/technical-support/pages/talk2m/talk2m-tools/talk2m-ecatcherVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.