Known Vulnerabilities for Ccu2 Firmware by Eq-3
Listed below are 8 of the newest known vulnerabilities associated with "Ccu2 Firmware" by "Eq-3".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-14475 json | eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization ch... | 7.5 - HIGH | 2019-08-05 | 2020-08-24 |
| CVE-2019-14473 json | eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest le... | 8.8 - HIGH | 2019-08-06 | 2020-08-24 |
| CVE-2019-14424 json | A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allo... | 6.5 - MEDIUM | 2019-10-17 | 2021-07-21 |
| CVE-2019-14423 json | A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 all... | 8.8 - HIGH | 2019-10-17 | 2021-07-21 |
| CVE-2019-10122 json | eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Ser... | 9.8 - CRITICAL | 2019-07-10 | 2021-07-21 |
| CVE-2019-10121 json | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authori... | 9.8 - CRITICAL | 2019-07-10 | 2020-08-24 |
| CVE-2019-10120 json | On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin... | 8.8 - HIGH | 2019-07-10 | 2019-07-17 |
| CVE-2019-10119 json | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authori... | 9.8 - CRITICAL | 2019-07-10 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Eq-3 | Ccu2 Firmware | 2.41.8 |