First published: Wed Aug 07 2019(Updated: )
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu3 Firmware | <=3.47.15 | |
Eq-3 Ccu3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14474 is a vulnerability in eQ-3 Homematic CCU3 3.47.15 and prior versions that allows an attacker to start a Denial of Service attack or obtain a session ID or a valid account.
CVE-2019-14474 has a severity rating of 7.5 (high).
CVE-2019-14474 affects eQ-3 Homematic CCU3 versions 3.47.15 and prior.
An attacker can exploit CVE-2019-14474 by utilizing improper authorization to obtain a session ID from CVE-2019-9583 or leveraging a valid guest/user/admin account to start a Denial of Service attack.
Yes, Eq-3 Ccu3 Firmware version 3.47.15 is vulnerable to CVE-2019-14474.