PT-2018-18006 · Eq 3 Ag · Homematic Ccu2
Gregor Kopf
+1
·
Publicado
2018-02-22
·
Atualizado
2019-10-03
·
CVE-2018-7298
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eQ-3 AG HomeMatic CCU2 version 2.29.22
Description
The issue concerns the download of software update packages via the HTTP protocol, which lacks cryptographic protection. An attacker with a privileged network position can exploit this to provide malicious firmware updates, potentially resulting in a full system compromise.
Recommendations
For eQ-3 AG HomeMatic CCU2 version 2.29.22, consider disabling the
loopupd.sh script in /usr/local/etc/config/addons/mh/ as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Homematic Ccu2