First published: Wed Jul 10 2019(Updated: )
On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu3 Firmware | <3.43.16 | |
Eq-3 Ccu3 | ||
Eq-3 Ccu2 Firmware | <2.41.8 | |
Eq-3 Ccu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10120 is a vulnerability that affects eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16.
CVE-2019-10120 allows an attacker to achieve automatic login configuration by continuing to use a session ID after a logout.
The severity of CVE-2019-10120 is high, with a CVSS score of 8.8.
eQ-3 HomeMatic CCU2 devices before version 2.41.8 and CCU3 devices before version 3.43.16 are affected by CVE-2019-10120.
To fix CVE-2019-10120, it is recommended to update the firmware of the affected eQ-3 HomeMatic CCU2 and CCU3 devices to versions 2.41.8 and 3.43.16 or later, respectively.