First published: Wed Jul 10 2019(Updated: )
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via the user authentication dialogue, aka HMCCU-153. This leads to automatic login as admin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu3 Firmware | <3.43.15 | |
Eq-3 Ccu3 | ||
Eq-3 Ccu2 Firmware | <2.41.8 | |
Eq-3 Ccu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-10121.
The severity rating for CVE-2019-10121 is 9.8 (critical).
CVE-2019-10121 is a vulnerability found in eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 that use session IDs for authentication but lack authorization checks, allowing an attacker to obtain a session ID via the user authentication dialogue and gain automatic login as admin.
CVE-2019-10121 affects eQ-3 HomeMatic CCU2 devices with firmware versions up to (but not including) 2.41.8, and CCU3 devices with firmware versions up to (but not including) 3.43.15.
To mitigate CVE-2019-10121, it is recommended to update the firmware of the affected devices to version 2.41.8 or higher for CCU2 and 3.43.15 or higher for CCU3.