First published: Thu Feb 22 2018(Updated: )
Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated attackers to create or overwrite arbitrary files or install malicious software on the device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Homematic Central Control Unit Ccu2 Firmware | <=2.29.22 | |
Eq-3 Homematic Central Control Unit Ccu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7299 is a vulnerability that allows authenticated attackers to create or overwrite arbitrary files or install malicious software on the eQ-3 AG Homematic CCU2 device during the addon installation process.
eQ-3 AG Homematic CCU2 version 2.29.2 and earlier are affected by CVE-2018-7299.
CVE-2018-7299 is considered a high severity vulnerability with a severity score of 8.
Authenticated attackers can exploit CVE-2018-7299 by creating or overwriting arbitrary files or installing malicious software on the eQ-3 AG Homematic CCU2 device during the addon installation process.
No, eQ-3 Homematic Central Control Unit Ccu2 is not vulnerable to CVE-2018-7299.