First published: Thu Oct 17 2019(Updated: )
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Cux-daemon | >=1.11a<=2.2.0 | |
Eq-3 Ccu2 Firmware | >=2.35.16<=2.45.6 | |
Eq-3 Ccu2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14424 is a Local File Inclusion (LFI) vulnerability in the CUx-Daemon addon of the eQ-3 Homematic CCU-Firmware.
CVE-2019-14424 allows remote authenticated attackers to read sensitive files in the eQ-3 Homematic CCU-Firmware via a simple HTTP request.
The CUx-Daemon addon version 1.11a of the eQ-3 Homematic CCU-Firmware from version 2.35.16 to 2.45.6 are affected by CVE-2019-14424.
CVE-2019-14424 has a severity rating of 6.5 (Medium).
To fix CVE-2019-14424, it is recommended to update the CUx-Daemon addon and the eQ-3 Homematic CCU-Firmware to the latest versions.