Vulnerability Description
eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eq-3 | Homematic Central Control Unit Ccu2 Firmware | 2.29.22 |
| Eq-3 | Homematic Central Control Unit Ccu2 | - |
Related Weaknesses (CWE)
References
- http://atomic111.github.io/article/homematic-ccu2-xml-rpcThird Party Advisory
- http://atomic111.github.io/article/homematic-ccu2-xml-rpcThird Party Advisory
FAQ
What is CVE-2018-7301?
CVE-2018-7301 is a vulnerability with a CVSS score of 9.8 (CRITICAL). eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices.
How severe is CVE-2018-7301?
CVE-2018-7301 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-7301?
Check the references section above for vendor advisories and patch information. Affected products include: Eq-3 Homematic Central Control Unit Ccu2 Firmware, Eq-3 Homematic Central Control Unit Ccu2.