← Back to CVE List

CVE-2019-10119

Published: 2019-07-10T12:15Z
Last Modified: 2024-11-21T04:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via an invalid login attempt to the RemoteApi account, aka HMCCU-154. This leads to automatic login as admin. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt