SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-16199

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

CRITICAL 9.8EPSS 8.74%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
8.74% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
eq-3/homematic ccu2 firmware · eq-3/homematic ccu3 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.