CVE-2019-10120

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2019
Last modified:
17/07/2019

Description

On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:eq-3:ccu3_firmware:*:*:*:*:*:*:*:* 3.43.16 (excluding)
cpe:2.3:h:eq-3:ccu3:-:*:*:*:*:*:*:*
cpe:2.3:o:eq-3:ccu2_firmware:*:*:*:*:*:*:*:* 2.41.8 (excluding)
cpe:2.3:h:eq-3:ccu2:-:*:*:*:*:*:*:*