CVE-2019-14473
06.08.2019, 19:15
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clear the system protocol or modify/delete internal programs, etc. pp.Enginsight
Vendor | Product | Version |
---|---|---|
eq-3 | ccu2_firmware | 𝑥 ≤ 2.47.15 |
eq-3 | ccu3_firmware | 𝑥 ≤ 3.47.15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration