Known Vulnerabilities for Ccu3 Firmware by Eq-3
Listed below are 10 of the newest known vulnerabilities associated with "Ccu3 Firmware" by "Eq-3".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-12834 json | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API... | 9.8 - CRITICAL | 2020-05-15 | 2020-05-21 |
| CVE-2019-14475 json | eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization ch... | 7.5 - HIGH | 2019-08-05 | 2020-08-24 |
| CVE-2019-14474 json | eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resultin... | 7.5 - HIGH | 2019-08-07 | 2019-08-16 |
| CVE-2019-14473 json | eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest le... | 8.8 - HIGH | 2019-08-06 | 2020-08-24 |
| CVE-2019-10122 json | eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Ser... | 9.8 - CRITICAL | 2019-07-10 | 2021-07-21 |
| CVE-2019-10121 json | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authori... | 9.8 - CRITICAL | 2019-07-10 | 2020-08-24 |
| CVE-2019-10120 json | On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin... | 8.8 - HIGH | 2019-07-10 | 2019-07-17 |
| CVE-2019-10119 json | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authori... | 9.8 - CRITICAL | 2019-07-10 | 2020-08-24 |
| CVE-2019-9727 json | Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows r... | 7.5 - HIGH | 2019-05-13 | 2020-08-24 |
| CVE-2019-9726 json | Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbit... | 7.5 - HIGH | 2019-05-13 | 2019-05-14 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Eq-3 | Ccu3 Firmware | 3.51.6 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 3.43.15 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 3.41.7 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 3.41.11 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 3.37.8 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.35.16 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.31.25 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.31.23 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.29.22-1 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.29.22 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.27.8-1 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.27.8 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.27.7 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.25.15 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.25.12 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.21.10 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.19.9-1 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.19.9 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.17.15 | |||
| Operating System | Eq-3 | Ccu3 Firmware | 2.15.5 |