PT-2018-18006 · Eq 3 Ag · Homematic Ccu2

Gregor Kopf

+1

·

Publicado

2018-02-22

·

Atualizado

2019-10-03

·

CVE-2018-7298

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eQ-3 AG HomeMatic CCU2 version 2.29.22
Description The issue concerns the download of software update packages via the HTTP protocol, which lacks cryptographic protection. An attacker with a privileged network position can exploit this to provide malicious firmware updates, potentially resulting in a full system compromise.
Recommendations For eQ-3 AG HomeMatic CCU2 version 2.29.22, consider disabling the loopupd.sh script in /usr/local/etc/config/addons/mh/ as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7298

Produtos afetados

Homematic Ccu2