CVE-2024-24578
RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple issues within the Java based `HMIPServer.jar` component. RaspberryMatric includes a Java based `HMIPServer`, that can be accessed through URLs starting with `/pages/jpages`. The `FirmwareController` class does however not perform any session id checks, thus this feature can be accessed without a valid session. Due to this issue, attackers can gain remote code execution as root user, allowing a full system compromise. Version 3.75.6.20240316 contains a patch.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.74% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-23, CWE-306
- Affected
- raspberrymatic/raspberrymatic
- Source
- security-advisories@github.com
References
- https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637hExploit, Vendor Advisory
- https://github.com/jens-maus/RaspberryMatic/security/advisories/GHSA-q967-q4j8-637hExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.