10
CVE-2018-7297
- EPSS 46.57%
- Veröffentlicht 22.02.2018 19:29:04
- Zuletzt bearbeitet 21.11.2024 04:11:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access and execute system commands on the device. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eq-3 ≫ Homematic Central Control Unit Ccu2 Firmware Version <= 2.29.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 46.57% | 0.976 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|