PT-2019-14575 · Eq 3 · Eq-3 Homematic Ccu2+1

Psytester

·

Publicado

2019-09-17

·

Atualizado

2020-08-24

·

CVE-2019-16199

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eQ-3 Homematic CCU2 versions prior to 2.47.18 eQ-3 Homematic CCU3 versions prior to 3.47.18
Description The issue allows remote code execution by unauthenticated attackers with access to the web interface. This is achieved via an HTTP POST request to certain URLs related to the ReGa core process.
Recommendations For eQ-3 Homematic CCU2 versions prior to 2.47.18, update to version 2.47.18 or later. For eQ-3 Homematic CCU3 versions prior to 3.47.18, update to version 3.47.18 or later.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16199

Produtos afetados

Eq-3 Homematic Ccu2
Eq-3 Homematic Ccu3