Vulnerability Description
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eq-3 | Homematic Ccu3 Firmware | 3.41.11 |
| Eq-3 | Homematic Ccu3 | - |
Related Weaknesses (CWE)
References
- https://noskill1337.github.io/homematic-ccu3-remote-code-executionExploitThird Party Advisory
- https://www.eq-3.com/products/homematic.htmlVendor Advisory
- https://noskill1337.github.io/homematic-ccu3-remote-code-executionExploitThird Party Advisory
- https://www.eq-3.com/products/homematic.htmlVendor Advisory
FAQ
What is CVE-2019-15850?
CVE-2019-15850 is a vulnerability with a CVSS score of 8.8 (HIGH). eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.
How severe is CVE-2019-15850?
CVE-2019-15850 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15850?
Check the references section above for vendor advisories and patch information. Affected products include: Eq-3 Homematic Ccu3 Firmware, Eq-3 Homematic Ccu3.