CVE-2018-7296
Last modified
CVE-2018-7296 is a vulnerability of currently unknown severity. Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eq-3 | Homematic Central Control Unit Ccu2 Firmware | <= 2.29.22 |
References
- http://atomic111.github.io/article/homematic-ccu2-filereadThird Party Advisory
- http://atomic111.github.io/article/homematic-ccu2-filereadThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7296?
How severe is CVE-2018-7296?
How do I fix CVE-2018-7296?
Are you affected by CVE-2018-7296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
