CVE-2024-22894
Last modified
CVE-2024-22894 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alpha-Innotec | Heat Pumps Firmware | < 2.88.3 |
| Alpha-Innotec | Heat Pumps Firmware | >= 3.0.0, < 3.89.0 |
| Alpha-Innotec | Heat Pumps Firmware | >= 4.0.0, < 4.81.3 |
| Novelan | Heat Pumps Firmware | < 2.88.3 |
| Novelan | Heat Pumps Firmware | >= 3.0.0, < 3.89.0 |
| Novelan | Heat Pumps Firmware | >= 4.0.0, < 4.81.3 |
References
- https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/Exploit, Third Party Advisory
- https://github.com/Jaarden/CVE-2024-22894Exploit, Third Party Advisory
- https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/Exploit, Third Party Advisory
- https://github.com/Jaarden/CVE-2024-22894Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-22894?
How severe is CVE-2024-22894?
How do I fix CVE-2024-22894?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-22880Cross Site Scripting vulnerability in Zadarma Zadarma extens…4.7
- CVE-2024-22889Due to incorrect access control in Plone version v6.0.9, rem…7.5
- CVE-2024-2289The PowerPack Lite for Beaver Builder plugin for WordPress i…5.4
- CVE-2024-22891Nteract v.0.28.0 was discovered to contain a remote code exe…9.8
- CVE-2024-22892OpenSlides 4.0.15 was discovered to be using a weak hashing …7.5
- CVE-2024-22893OpenSlides 4.0.15 verifies passwords by comparing password h…7.5
- CVE-2024-22895DedeCMS 5.7.112 has a File Upload vulnerability via uploads/…8.8
- CVE-2024-22899Vinchin Backup & Recovery v7.2 was discovered to contain an …8.8
- CVE-2024-2290The Advanced Ads plugin for WordPress is vulnerable to PHP O…7.2
- CVE-2024-22900Vinchin Backup & Recovery v7.2 was discovered to contain an …8.8
- CVE-2024-22901Vinchin Backup & Recovery v7.2 was discovered to use default…9.8
- CVE-2024-22902Vinchin Backup & Recovery v7.2 was discovered to be configur…9.8
Are you affected by CVE-2024-22894?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
