PT-2019-13911 · Eq 3 · Homematic Ccu2+1

Psytester

·

Publicado

2019-08-13

·

Atualizado

2020-08-24

·

CVE-2019-14984

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eQ-3 Homematic CCU2 and CCU3 versions prior to 1.2.0 AddOn
Description The issue allows remote code execution by unauthenticated attackers with access to the web interface. This is because the undocumented script addons/xmlapi/exec.cgi uses CMD EXEC to execute TCL code from a POST request to the "XML-API".
Recommendations For versions prior to 1.2.0 AddOn, as a temporary workaround, consider disabling the exec.cgi script in the addons/xmlapi directory until a patch is available. Restrict access to the XML-API to minimize the risk of exploitation. Avoid using the XML-API until the issue is resolved.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14984

Produtos afetados

Homematic Ccu2
Homematic Ccu3