CVE Feed

    Dashboard / CVE / CVE-2019-9727

    CVE-2019-9727

    Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

    Published:May 13, 2019
    Last Modified:Nov 21, 2024
    EPS:May 13, 2019
    EPSS Score:0.0044
    CVSS Score:7.5

    Affected Products

    Vendor
    Eq-3
    Product
    Ccu3
    Vendor
    Eq-3
    Product
    Ccu3 Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High