PT-2019-19825 · Eq 3 Ag · Homematic Ccu3

Lukas Zorn

+3

·

Publicado

2019-05-13

·

Atualizado

2020-08-24

·

CVE-2019-9727

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions eQ-3 AG Homematic CCU3 versions 3.43.15 and earlier
Description The issue allows unauthenticated remote attackers to disclose password hashes of GUI users through the User.getUserPWD method. This can be exploited by attackers with access to the web interface.
Recommendations For versions 3.43.15 and earlier, update to a version that fixes this issue to prevent unauthenticated password hash disclosure. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9727

Produtos afetados

Homematic Ccu3