Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2021-33032EPSS 52% A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 fi… Homematic Ccu2 Firmware after 3.57.5 Fix from $2,3002021-07-22 CRITICAL 9.8 CVE-2020-12834EPSS 11% eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, … Homematic Ccu2 Firmware after 3.51.6 Fix from $2,3002020-05-15 HIGH 8.8 CVE-2019-14423EPSS 20% A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated… Cux Daemon after 2.45.6 Fix from $1,9502019-10-17 HIGH 8.8 CVE-2019-15850EPSS 16% eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute … Homematic Ccu3 Firmware No fix yet Fix from $1,9502019-10-17 HIGH 7.3 CVE-2019-15849 eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs i… Homematic Ccu3 Firmware No fix yet Fix from $1,9502019-10-17 MEDIUM 6.5 CVE-2019-14424 A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated … Cux Daemon after 2.45.6 Fix from $1,6002019-10-17 CRITICAL 9.8 CVE-2019-16199EPSS 9% eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface … Homematic Ccu2 Firmware 2.47.18 / 3.47.18+ Fix from $2,3002019-09-17 CRITICAL 9.8 CVE-2019-9584 eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting… Homematic Ccu2 Firmware after 3.47.15 Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2019-9585 eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, res… Homematic Ccu2 Firmware 2.47.10 / 3.47.10+ Fix from $2,3002019-08-14 HIGH 8.2 CVE-2019-9583 eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected ve… Homematic Ccu3 Firmware No fix yet Fix from $1,9502019-08-14 HIGH 7.5 CVE-2019-9582 eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7… Homematic Ccu2 Firmware No fix yet Fix from $1,9502019-08-14 CRITICAL 9.8 CVE-2019-14985EPSS 8% eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface,… Homematic Ccu2 Firmware No fix yet Fix from $2,3002019-08-13 HIGH 8.1 CVE-2019-14984EPSS 6% eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to t… Homematic Ccu2 Firmware after 1.2.0 Fix from $1,9502019-08-13 HIGH 8.1 CVE-2019-14986 eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to t… Homematic Ccu2 Firmware 2.3.0+ Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-14474 eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to star… Ccu3 Firmware after 3.47.15 Fix from $1,9502019-08-07 HIGH 8.8 CVE-2019-14473 eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level accoun… Ccu2 Firmware after 3.47.15 Fix from $1,9502019-08-06 HIGH 7.5 CVE-2019-14475 eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can ob… Ccu2 Firmware after 3.47.15 Fix from $1,9502019-08-05 CRITICAL 9.8 CVE-2019-10119 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attack… Ccu3 Firmware 2.41.8 / 3.43.16+ Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-10121 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attack… Ccu3 Firmware 2.41.8 / 3.43.15+ Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-10122 eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component, aka H… Ccu3 Firmware 2.41.9 / 3.43.16+ Fix from $2,3002019-07-10 HIGH 8.8 CVE-2019-10120 On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by con… Ccu3 Firmware 2.41.8 / 3.43.16+ Fix from $1,9502019-07-10 HIGH 7.5 CVE-2019-9727 Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retri… Ccu3 Firmware after 3.43.15 Fix from $1,9502019-05-13 HIGH 7.5 CVE-2019-9726EPSS 16% Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device… Ccu3 Firmware after 3.43.15 Fix from $1,9502019-05-13 CRITICAL 9.8 CVE-2018-7301 eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests … Homematic Central Control Unit Ccu2 Firmware Mitigation only Fix from $2,3002018-02-22 CRITICAL 9.8 CVE-2018-7300EPSS 31% Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows… Homematic Ccu2 Firmware after 2.29.22 Fix from $2,3002018-02-22 HIGH 8.1 CVE-2018-7298 In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protoco… Homematic Central Control Unit Ccu2 Firmware Mitigation only Fix from $1,9502018-02-22 HIGH 8.0 CVE-2018-7299 Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated attackers to create or over… Homematic Central Control Unit Ccu2 Firmware after 2.29.22 Fix from $1,9502018-02-22 CRITICAL 9.8 CVE-2018-7297EPSS 64% Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access … Homematic Central Control Unit Ccu2 Firmware after 2.29.22 Fix from $2,3002018-02-22 MEDIUM 5.3 CVE-2018-7296 Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the… Homematic Central Control Unit Ccu2 Firmware after 2.29.22 Fix from $1,6002018-02-22