Back to search
CVE-2019-14475
Published: Aug 5, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read the service messages, clear the system protocol, create a new user in the system, or modify/delete internal programs.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://psytester.github.io/CVE-2019-14475
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now