First published: Wed Aug 14 2019(Updated: )
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eQ-3 HomeMatic CCU2 firmware | <2.47.10 | |
eQ-3 Homematic CCU2 | ||
eQ-3 HomeMatic CCU3 firmware | <3.47.10 | |
eQ-3 HomeMatic CCU3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9585 is a vulnerability in eQ-3 Homematic CCU2 and CCU3 JSON API that allows improper access control for Metadata operations.
CVE-2019-9585 has a severity rating of 9.8 (Critical).
CVE-2019-9585 affects eQ-3 Homematic CCU2 versions prior to 2.47.10, allowing unauthorized access to Metadata operations.
CVE-2019-9585 affects eQ-3 Homematic CCU3 versions prior to 3.47.10, allowing unauthorized access to Metadata operations.
To fix CVE-2019-9585, update eQ-3 Homematic CCU2 to version 2.47.10 or later, and update eQ-3 Homematic CCU3 to version 3.47.10 or later.