Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Homematic Ccu3 Firmware HIGH 8.8
CVE-2019-15850EPSS 16%

eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute …

No fix yet
Fix from $1,950 2019-10-17
Homematic Ccu3 Firmware HIGH 7.3
CVE-2019-15849

eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs i…

No fix yet
Fix from $1,950 2019-10-17
Homematic Ccu3 Firmware HIGH 8.2
CVE-2019-9583

eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve…

No fix yet
Fix from $1,950 2019-08-14
Homematic Ccu2 Firmware HIGH 7.5
CVE-2019-9582

eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7…

No fix yet
Fix from $1,950 2019-08-14
Homematic Ccu2 Firmware CRITICAL 9.8
CVE-2019-14985EPSS 8%

eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,…

No fix yet
Fix from $2,300 2019-08-13
Homematic Central Control Unit Ccu2 Firmware CRITICAL 9.8
CVE-2018-7301

eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests …

Mitigation only
Fix from $2,300 2018-02-22
Homematic Central Control Unit Ccu2 Firmware HIGH 8.1
CVE-2018-7298

In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco…

Mitigation only
Fix from $1,950 2018-02-22