CVE-2024-42469
- EPSS 13.82%
- Veröffentlicht 12.08.2024 13:38:35
- Zuletzt bearbeitet 12.09.2024 16:02:35
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometVisu's file system endpoints don't require authentication and additionally the endpoint to update an e...
CVE-2024-42470
- EPSS 0.59%
- Veröffentlicht 12.08.2024 13:38:35
- Zuletzt bearbeitet 12.09.2024 16:04:23
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions prior to 4.2.1 of the CometVisu add-on of openHAB don't require authentication. This makes it possibl...
CVE-2024-42468
- EPSS 1.56%
- Veröffentlicht 12.08.2024 13:38:34
- Zuletzt bearbeitet 12.09.2024 16:01:42
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an unauthenticated path traversal vulnerability. Local files on the s...
- EPSS 0.36%
- Veröffentlicht 01.02.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:53
openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve inter...
CVE-2020-5242
- EPSS 0.72%
- Veröffentlicht 20.02.2020 23:15:20
- Zuletzt bearbeitet 21.11.2024 05:33:44
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all co...