First published: Mon Aug 05 2019(Updated: )
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a new user in the system, or modify/delete internal programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu2 Firmware | <=2.47.15 | |
Eq-3 Ccu2 | ||
Eq-3 Ccu3 Firmware | <=3.47.15 | |
Eq-3 Ccu3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14475 is a vulnerability in eQ-3 Homematic CCU2 and CCU3 that allows an attacker to obtain a session ID and perform unauthorized actions.
CVE-2019-14475 has a severity rating of 7.5 (high).
eQ-3 Homematic CCU2 versions up to 2.47.15 and CCU3 versions up to 3.47.15 are affected by CVE-2019-14475.
An attacker can read service messages, clear the system protocol, and create a new user in the system using CVE-2019-14475.
No specific fix information is provided for CVE-2019-14475. It is recommended to check with the vendor for any available updates or patches.