eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request
Published Nov 14, 2019
9.8
CRITICALCVSS 3.1
EPSS 33.84%
Description
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.
Affected products
No data.
Configuration 1
- 1.8
- 2.47.20
Running on/with
- n/a
Configuration 2
- 1.8
- 3.47.18
Running on/with
- n/a
Configuration 3
- 1.7
- 3.47.18
Running on/with
- n/a
Configuration 4
- 1.7
- 2.47.20
Running on/with
- n/a
Configuration 5
- 1.6
- 2.47.20
Running on/with
- n/a
Configuration 6
- 1.5
- 2.47.20
Running on/with
- n/a
Configuration 7
- 1.4
- 2.47.20
Running on/with
- n/a
Configuration 8
- 1.3
- 2.47.20
Running on/with
- n/a
Configuration 9
- 1.3
- 2.47.20
Running on/with
- n/a
Configuration 10
- 1.2
- 2.47.20
Running on/with
- n/a
Configuration 11
- 1.0
- 2.47.20
Running on/with
- n/a
Configuration 12
- 1.6
- 3.47.18
Running on/with
- n/a
Configuration 13
- 1.5
- 3.47.18
Running on/with
- n/a
Configuration 14
- 1.4
- 3.47.18
Running on/with
- n/a
Configuration 15
- 1.3
- 3.47.18
Running on/with
- n/a
Configuration 16
- 1.3
- 3.47.18
Running on/with
- n/a
Configuration 17
- 1.2
- 3.47.18
Running on/with
- n/a
Configuration 18
- 1.0
- 3.47.18
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://psytester.github.io/CVE-2019-18937/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://psytester.github.io/CVE-2019-18937/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.