Описание
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.47.15 (включая)
Одновременно
cpe:2.3:o:eq-3:homematic_ccu2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu2:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 3.47.15 (включая)
Одновременно
cpe:2.3:o:eq-3:homematic_ccu3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:eq-3:homematic_ccu3:-:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00448
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-425
Связанные уязвимости
github
больше 3 лет назад
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
EPSS
Процентиль: 63%
0.00448
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-425