PT-2019-11585 · Rega Ise Gmbh+1 · Rega Ise Gmbh Http-Server+2

Published

2019-07-10

·

Updated

2021-07-21

·

CVE-2019-10122

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: eQ-3 HomeMatic CCU2 versions prior to 2.41.9 eQ-3 HomeMatic CCU3 versions prior to 3.43.16
Description: The issue is related to buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component. This may lead to remote code execution.
Recommendations: For eQ-3 HomeMatic CCU2 versions prior to 2.41.9, update to version 2.41.9 or later. For eQ-3 HomeMatic CCU3 versions prior to 3.43.16, update to version 3.43.16 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10122

Affected Products

Rega Ise Gmbh Http-Server
Eq-3 Homematic Ccu2
Eq-3 Homematic Ccu3