CVE-2024-22894

EUVD-2024-20419
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
alpha-innotecheat_pumps_firmware
𝑥
< 2.88.3
alpha-innotecheat_pumps_firmware
3.0.0 ≤
𝑥
< 3.89.0
alpha-innotecheat_pumps_firmware
4.0.0 ≤
𝑥
< 4.81.3
novelanheat_pumps_firmware
𝑥
< 2.88.3
novelanheat_pumps_firmware
3.0.0 ≤
𝑥
< 3.89.0
novelanheat_pumps_firmware
4.0.0 ≤
𝑥
< 4.81.3
𝑥
= Vulnerable software versions