HMS Networks Update
3112Warning Date
Severity Level
Warning Number
Target Sector
13 September, 2020
● Low
2020-1764
Energy - Water and Utilities - Manufacturing - Commercial Facilities
Description:
HMS Networks has released a security update to address a vulnerability in the following product:
- Flexy and Cosy
- All versions prior to 14.1
Threats:
Attacker could exploit the vulnerability by injecting scripts into the Cross-origin Resource Sharing (CORS) configuration that could lead to retrieve limited confidential information.
Best practice and Recommendations:
The CERT team encourages users to review HMS Networks security advisory and apply the necessary update: