VYPR

Ccu2 Firmware

by eQ-3

CVEs (22)

  • CVE-2019-14475HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.02

    eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a…

  • CVE-2019-14424MedOct 17, 2019
    risk 0.42cvss 6.5epss 0.01

    A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.

Page 2 of 2