CVE-2024-22894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
30/01/2024
Last modified:
29/08/2024

Description

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:* 2.88.3 (excluding)
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:* 3.0.0 (including) 3.89.0 (excluding)
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:* 4.0.0 (including) 4.81.3 (excluding)
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:* 2.88.3 (excluding)
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:* 3.0.0 (including) 3.89.0 (excluding)
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:* 4.0.0 (including) 4.81.3 (excluding)
cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*