VYPR

Ccu3 Firmware

by eQ-3

CVEs (23)

  • CVE-2019-14475HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.02

    eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a…

  • CVE-2019-9727HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.02

    Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exploited by unauthenticated attackers with access to the web…

  • CVE-2019-15849HigOct 17, 2019
    risk 0.48cvss 7.3epss 0.01

    eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could create SSH logins after a valid session and easily…

Page 2 of 2