9.8
CVE-2019-9584
- EPSS 0.45%
- Veröffentlicht 14.08.2019 21:15:19
- Zuletzt bearbeitet 21.11.2024 04:51:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eq-3 ≫ Homematic Ccu2 Firmware Version <= 2.47.15
Eq-3 ≫ Homematic Ccu3 Firmware Version <= 3.47.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.627 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.