← Back

CVE-2019-15849

nvd nist
Published: Oct 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.1 / Impact: 5.2
Source: NVD

Description

eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that session. The attacker could create SSH logins after a valid session and easily compromise the system.

Affected (1)

1 product
Homematic Ccu3 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.14.11
Running on/withPlatform Versions
Eq 3
Homematic Ccu3
All versions

References (4)

Source: cve@mitre.org
ExploitMitigationThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.