PT-2018-18006 · Eq 3 Ag · Homematic Ccu2
Gregor Kopf
+1
·
Published
2018-02-22
·
Updated
2019-10-03
·
CVE-2018-7298
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
eQ-3 AG HomeMatic CCU2 version 2.29.22
Description
The issue concerns the download of software update packages via the HTTP protocol, which lacks cryptographic protection. An attacker with a privileged network position can exploit this to provide malicious firmware updates, potentially resulting in a full system compromise.
Recommendations
For eQ-3 AG HomeMatic CCU2 version 2.29.22, consider disabling the
loopupd.sh script in /usr/local/etc/config/addons/mh/ as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homematic Ccu2