Show filters
664 Total Results
Displaying 401-410 of 664
Sort by:
Attacker Value
Unknown
CVE-2019-16199
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.
0
Attacker Value
Unknown
CVE-2010-5333
Disclosure Date: September 13, 2019 (last updated February 15, 2024)
The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution. An SEH-overwrite buffer overflow already existed for the vulnerable software. This CVE is to track an alternate exploitation method, utilizing an EIP-overwrite buffer overflow.
0
Attacker Value
Unknown
SmartHome application has a broken access control vulnerability in its Web API …
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
0
Attacker Value
Unknown
CVE-2019-6178
Disclosure Date: August 19, 2019 (last updated November 27, 2024)
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
0
Attacker Value
Unknown
CVE-2019-9585
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata.
0
Attacker Value
Unknown
CVE-2019-9584
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
0
Attacker Value
Unknown
CVE-2019-9582
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7, 2.47.10, 2.47.12, 2.47.15.
0
Attacker Value
Unknown
CVE-2019-9583
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected versions for CCU2: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7, 2.47.10, 2.47.12, 2.47.15. Affected versions for CCU3: 3.41.11, 3.43.16, 3.45.5, 3.45.7, 3.47.10, 3.47.15.
0
Attacker Value
Unknown
CVE-2019-14986
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.
0
Attacker Value
Unknown
CVE-2019-14985
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
0