CVE-2024-22894

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
alpha-innotecheat_pumps_firmware
𝑥
< 2.88.3
alpha-innotecheat_pumps_firmware
3.0.0 ≤
𝑥
< 3.89.0
alpha-innotecheat_pumps_firmware
4.0.0 ≤
𝑥
< 4.81.3
novelanheat_pumps_firmware
𝑥
< 2.88.3
novelanheat_pumps_firmware
3.0.0 ≤
𝑥
< 3.89.0
novelanheat_pumps_firmware
4.0.0 ≤
𝑥
< 4.81.3
𝑥
= Vulnerable software versions