← Back

CVE-2024-22894

nvd nist
Published: Jan 30, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

Affected (6)

1 product
Heat Pumps Firmware
1 product
Heat Pumps Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Alpha Innotec
Before 2.88.3
From 3.0.0 to 3.89.0
From 4.0.0 to 4.81.3
Running on/withPlatform Versions
Alpha Innotec
Heat Pumps
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Novelan
Before 2.88.3
From 3.0.0 to 3.89.0
From 4.0.0 to 4.81.3
Running on/withPlatform Versions
Novelan
Heat Pumps
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.