First published: Mon May 13 2019(Updated: )
Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eq-3 Ccu3 Firmware | <=3.43.15 | |
Eq-3 Ccu3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9727 is a vulnerability that allows remote attackers to retrieve the GUI password hashes of GUI users in eQ-3 AG Homematic CCU3 3.43.15 and earlier.
CVE-2019-9727 has a severity rating of 7.5 (high).
CVE-2019-9727 allows unauthenticated attackers with access to the web interface to retrieve the password hashes of GUI users.
Yes, Eq-3 Ccu3 firmware version up to 3.43.15 is affected by CVE-2019-9727.
To fix CVE-2019-9727, update the eQ-3 AG Homematic CCU3 firmware to a version that is not vulnerable.