PT-2018-18006 · Eq 3 Ag · Homematic Ccu2

Gregor Kopf

+1

·

Published

2018-02-22

·

Updated

2019-10-03

·

CVE-2018-7298

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eQ-3 AG HomeMatic CCU2 version 2.29.22
Description The issue concerns the download of software update packages via the HTTP protocol, which lacks cryptographic protection. An attacker with a privileged network position can exploit this to provide malicious firmware updates, potentially resulting in a full system compromise.
Recommendations For eQ-3 AG HomeMatic CCU2 version 2.29.22, consider disabling the loopupd.sh script in /usr/local/etc/config/addons/mh/ as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7298

Affected Products

Homematic Ccu2