Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a new user in the system, or modify/delete internal programs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eQ-3 HomeMatic CCU2和eQ-3 Homematic CCU3 授权问题漏洞
Vulnerability Description
eQ-3 Homematic CCU3和eQ-3 HomeMatic CCU2都是德国eQ-3公司的一款智能家居系统的中央控制单元。 eQ-3 Homematic CCU2 2.47.15及之前版本和eQ-3 Homematic CCU3 3.47.15及之前版本中存在安全漏洞,该漏洞源于程序使用会话ID来进行身份验证但缺少授权检查。攻击者可利用该漏洞读取服务的消息,清除系统协议,创建新用户或修改/删除内部程序。
CVSS Information
N/A
Vulnerability Type
N/A